pagetriage-welcome was not escaped or sanitized, because it was using raw HTML deliberately for links. However, this meant it didn't go through the sanitizer, so admins could have added other less friendly HTML.
Description
Description
Details
Details
Project | Branch | Lines +/- | Subject | |
---|---|---|---|---|
mediawiki/extensions/PageTriage | master | +31 -30 | Fix unsanitized message |
Status | Subtype | Assigned | Task | ||
---|---|---|---|---|---|
Open | None | T2212 Some MediaWiki: messages not safe in HTML (tracking) | |||
Invalid | None | T85864 Special pages, actions and views whose messages don't escape text | |||
Resolved | • Mattflaschen-WMF | T112469 Fix unsanitized message in PageTriage |
Event Timeline
Comment Actions
Change 238000 had a related patch set uploaded (by Mattflaschen):
Fix unsanitized message