Page Menu
Home
Phabricator
Search
Configure Global Search
Log In
Files
F8516186
0001-SECURITY-script-tags-should-be-stripped-from-extract.patch
Jdlrobson (Jon Robson)
Actions
View File
Edit File
Delete File
View Transforms
Subscribe
Mute Notifications
Award Token
Flag For Later
Authored By
Jdlrobson
Jun 23 2017, 6:11 PM
2017-06-23 18:11:51 (UTC+0)
Size
881 B
Referenced Files
None
Subscribers
None
0001-SECURITY-script-tags-should-be-stripped-from-extract.patch
View Options
From 0b0c60e42fff485349c33acf409eca73dd476c2a Mon Sep 17 00:00:00 2001
From: jdlrobson <jdlrobson@gmail.com>
Date: Fri, 23 Jun 2017 11:10:25 -0700
Subject: [PATCH] SECURITY: script tags should be stripped from extracts
Bug: T107206
Change-Id: I268a5de006867058b23e6146f00a990a39894ae1
---
wmf-config/InitialiseSettings.php | 2 ++
1 file changed, 2 insertions(+)
diff --git a/wmf-config/InitialiseSettings.php b/wmf-config/InitialiseSettings.php
index e070459..26c41e2 100644
--- a/wmf-config/InitialiseSettings.php
+++ b/wmf-config/InitialiseSettings.php
@@ -15026,6 +15026,8 @@ $wgConf->settings = [
'.metadata',
// b/c rules, @todo: consider just whacking class="noexcerpt" on these
'span.coordinates', 'span.geo-multi-punct', 'span.geo-nondefault', '#coordinates',
+ // T107206
+ 'script'
],
],
'wgExtractsExtendOpenSearchXml' => [
--
2.10.1 (Apple Git-78)
File Metadata
Details
Attached
Mime Type
text/x-diff
Storage Engine
blob
Storage Format
Raw Data
Storage Handle
4735811
Default Alt Text
0001-SECURITY-script-tags-should-be-stripped-from-extract.patch (881 B)
Attached To
Mode
T107206: TextExtracts should strip scripts
Attached
Detach File
Event Timeline
Log In to Comment