Page MenuHomePhabricator

DisplayTitle in CommentStreams author is visually HTML escaped
Closed, ResolvedPublicBUG REPORT

Description

Steps to replicate the issue (include links if applicable):

  • Have Extension:CommentStreams and Extension:DisplayTitle on a wiki
  • Set a {{DISPLAYTITLE}} with HTML or wikitext formatting on your userpage
  • Leave a comment via CommentStreams

What happens?:
The name of the commenter appears fully HTML escaped (i.e. <span style="color:orange"><b>miraheze enjoyer</b></span>)

What should have happened instead?:
EITHER the name renders the intended styling tags:

  • <span style="color:orange">miraheze enjoyer</span> (tags rendered)

HTML is escaped and removed, leaving only wikitext tags(bold, italics):

  • miraheze enjoyer

or all formatting and tags are just removed entirely and not shown:

  • miraheze enjoyer

Software version (on Special:Version page; skip for WMF-hosted wikis like Wikipedia):
MediaWiki: 1.43.0-alpha (566b8c4) &: 2.3 (db1014c)
CommentStreams: 8.0.2 (rECOS1283fe65f03d: Localisation updates from https://translatewiki.net.)
Display Title: 4.0.3 (rEDPT2a839e7640dc: build: Updating micromatch to 4.0.8)
Other information (browser name/version, screenshots, etc.):

image.png (49×565 px, 5 KB)

Event Timeline

BlankEclair subscribed.

The bug still happens without Extension:DisplayTitle:

Screenshot 2024-12-13 at 15-19-39 my_wiki.png (1×3 px, 364 KB)

Screenshot 2024-12-13 at 15-19-47 Version - my_wiki.png (302×2 px, 68 KB)

Change #1103103 had a related patch set uploaded (by BlankEclair; author: BlankEclair):

[mediawiki/extensions/CommentStreams@master] Fix HTML in display title being escaped

https://gerrit.wikimedia.org/r/1103103

Change #1103103 merged by jenkins-bot:

[mediawiki/extensions/CommentStreams@master] Fix HTML in display title being escaped

https://gerrit.wikimedia.org/r/1103103

Change #1112395 had a related patch set uploaded (by MarkAHershberger; author: BlankEclair):

[mediawiki/extensions/CommentStreams@REL1_43] Fix HTML in display title being escaped

https://gerrit.wikimedia.org/r/1112395

Change #1112395 merged by jenkins-bot:

[mediawiki/extensions/CommentStreams@REL1_43] Fix HTML in display title being escaped

https://gerrit.wikimedia.org/r/1112395

Change #1112441 had a related patch set uploaded (by BlankEclair; author: BlankEclair):

[mediawiki/extensions/CommentStreams@REL1_42] Fix HTML in display title being escaped

https://gerrit.wikimedia.org/r/1112441

Change #1112442 had a related patch set uploaded (by BlankEclair; author: BlankEclair):

[mediawiki/extensions/CommentStreams@REL1_39] Fix HTML in display title being escaped

https://gerrit.wikimedia.org/r/1112442

Change #1112442 merged by jenkins-bot:

[mediawiki/extensions/CommentStreams@REL1_39] Fix HTML in display title being escaped

https://gerrit.wikimedia.org/r/1112442

Change #1112441 merged by jenkins-bot:

[mediawiki/extensions/CommentStreams@REL1_42] Fix HTML in display title being escaped

https://gerrit.wikimedia.org/r/1112441