Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/tools/cmd/godoc: switch to use html/template #4655

Open
adg opened this issue Jan 13, 2013 · 5 comments
Open

x/tools/cmd/godoc: switch to use html/template #4655

adg opened this issue Jan 13, 2013 · 5 comments
Labels
Milestone

Comments

@adg
Copy link
Contributor

adg commented Jan 13, 2013

Godoc should use the auto-escaping htm/template package instead of text/template, for
security reasons.

With text/template, it is hard to write UI code that doesn't introduce content injection
vulnerabilities.
@adg
Copy link
Contributor Author

adg commented Mar 18, 2013

Comment 2:

Labels changed: added godoc.

@rsc
Copy link
Contributor

rsc commented Nov 27, 2013

Comment 3:

Labels changed: added go1.3maybe.

@rsc
Copy link
Contributor

rsc commented Dec 4, 2013

Comment 4:

Labels changed: added release-none, removed go1.3maybe.

@rsc
Copy link
Contributor

rsc commented Dec 4, 2013

Comment 5:

Labels changed: added repo-tools.

@rsc rsc added this to the Unplanned milestone Apr 10, 2015
@rsc rsc changed the title cmd/godoc: switch to use html/template x/tools/cmd/godoc: switch to use html/template Apr 14, 2015
@rsc rsc removed the repo-tools label Apr 14, 2015
@gopherbot
Copy link
Contributor

Change https://golang.org/cl/70935 mentions this issue: godoc: switch to use html/template

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants