Page MenuHomePhabricator

have phan-taint-check look for the "help" key in HTMLForm specifiers
Closed, ResolvedPublic

Description

Currently MWVisitor::detectHTMLForm tries to do some checking of html form specifiers. It currently does not check the 'help' key. However, that key is raw html so we should add it.

Event Timeline

Change 963145 had a related patch set uploaded (by Daimona Eaytoy; author: Daimona Eaytoy):

[mediawiki/tools/phan/SecurityCheckPlugin@master] MW: Detect tainted `help` HTMLForm property

https://gerrit.wikimedia.org/r/963145

Change 963145 merged by jenkins-bot:

[mediawiki/tools/phan/SecurityCheckPlugin@master] MW: Detect tainted `help` HTMLForm property

https://gerrit.wikimedia.org/r/963145