Skip to content

Conversation

@gocom
Copy link
Contributor

@gocom gocom commented Mar 1, 2019

Also prevent the whole page from breaking on a XML parsing error due to an exception not being caught. The language ID was removed due to security too; user-given values (like these remote values are) are not safe to be used as a IDs and would need to be filtered properly before use.

As I do not have a API key for the said service (and its lazy Friday night) the code is untested, but should function just fine.

Also prevent the whole page from breaking on a XML parsing error
due to an exception not being caught.
@gocom gocom changed the title Sanitize remote variable used in the language table Sanitize remote variables used in the language table Mar 1, 2019
@philwareham
Copy link
Member

Thanks again @gocom!

@philwareham philwareham merged commit 2e2fdfd into textpattern:master Mar 4, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants