As a library (the html table building classes), both HtmlTableHeaderBuilder and HtmlTableCellBuilder need to escape their output by default, and have a class / function / flag, that is clearly named (should probably have "raw" or "nonEscaped" in the name), that allows the library user to put raw html into the table headers/cells.
Description
Description
Status | Subtype | Assigned | Task | ||
---|---|---|---|---|---|
Resolved | Lydia_Pintscher | T99351 Review and deploy Wikibase-Quality on wikidata.org | |||
Resolved | • csteipp | T99352 Security review of Wikibase-Quality | |||
Resolved | • csteipp | T102649 Ex:WikibaseQuality - Needs to escape output by default |
Event Timeline
Comment Actions
Change 219174 had a related patch set uploaded (by Dominic.sauer):
T102649 Allow raw content for html builder, escape content by default
Comment Actions
Change 219180 had a related patch set uploaded (by Soeren.oldag):
T102649 Allow raw content for html builder, escape content by default
Comment Actions
Change 219180 merged by Soeren.oldag:
T102649 Allow raw content for html builder, escape content by default
Comment Actions
Change 219174 merged by Soeren.oldag:
T102649 Allow raw content for html builder, escape content by default