Page MenuHomePhabricator

Ensure html in data-mw can't be manipulated by attacker before being loaded on ContentTranslation
Closed, InvalidPublic

Description

Currently, this is prevented by checking the typeof attribute on the reference element, but if a wiki sets $wgAllowRdfaAttributes = true, this will no longer be effective.

Event Timeline

csteipp raised the priority of this task from to Needs Triage.
csteipp updated the task description. (Show Details)
csteipp subscribed.
Nikerabbit triaged this task as High priority.
Nikerabbit set Security to None.

Per private email conversations (sorry about that) this is in fact not an issue. Parsoid will prefix conflicting data and typeof attributes.