Skip to content

Conversation

@ThiefMaster
Copy link
Member

There were also two cases of catastrophic backtracking in regexps which I didn't fix as those are in client-side code where the user could only slow down their own browser, so it's not really worth touching that legacy code...

Most places where it was missing were internal links and thus safe, but
there's no need to have opener/referrer for those either, so no need to
get warnings from code analysis tools that need to be silenced...
@ThiefMaster ThiefMaster merged commit 5a50973 into indico:2.3-maintenance May 10, 2021
@ThiefMaster ThiefMaster deleted the xss branch May 10, 2021 14:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant