Page MenuHomePhabricator

Media file metadata should not be parsed
Open, LowPublic

Description

The HTML table constructed from file metadata that's displayed at the bottom of file pages is sent through the parser. That probably should not happen.

Event Timeline

Tgr created this task.Oct 29 2015, 11:30 PM
Tgr raised the priority of this task from to Needs Triage.
Tgr updated the task description. (Show Details)
Tgr added a project: MediaWiki-File-management.
Tgr added a subscriber: Tgr.
Restricted Application added a project: Multimedia. · View Herald TranscriptOct 29 2015, 11:30 PM
Restricted Application added subscribers: Steinsplitter, Aklapper. · View Herald Transcript

One nice thing though, is this makes it easy to see that there's no possible XSS in any of the metadata handlers.

Restricted Application added a subscriber: Matanya. · View Herald TranscriptOct 29 2015, 11:31 PM
Tgr added a comment.Oct 29 2015, 11:33 PM

Maybe it should be sanitized but not parsed?

MarkTraceur triaged this task as Low priority.Dec 21 2015, 9:40 PM
MarkTraceur added a subscriber: MarkTraceur.
Restricted Application added a project: Commons. · View Herald TranscriptDec 21 2015, 9:40 PM
zhuyifei1999 moved this task from Incoming to Backlog on the Commons board.Jan 2 2016, 6:43 AM
MarkTraceur moved this task from Untriaged to Triaged on the Multimedia board.Dec 6 2016, 4:12 PM
Restricted Application added a subscriber: Poyekhali. · View Herald TranscriptDec 6 2016, 4:12 PM