[ 
http://jira.magnolia-cms.com/browse/MGNLFORM-142?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jan Haderka reopened MGNLFORM-142:
----------------------------------


Since you add loading of params from request in this ticket, you also need to 
add tests for XSS attack to the tests to make sure JS is escaped when someone 
attempts to inject it.

The relation should be set as dependency ... pur ticket depends on this to get 
fixed. Also associated support ticket is against Magnolia 4.4 which was 
released w/ Form 1.2.x and Pur 1.3.x if I'm not mistaken so you need to 
backport your changes as well.

> Parameters in URL are everytime lost after form submission
> ----------------------------------------------------------
>
>                 Key: MGNLFORM-142
>                 URL: http://jira.magnolia-cms.com/browse/MGNLFORM-142
>             Project: Magnolia Form Module
>          Issue Type: Bug
>            Reporter: Jaroslav Simak
>            Assignee: Jaroslav Simak
>             Fix For: 1.4.4
>
>
> Suppose we have page with form and user entered here from this url 
> {{www.example.com/some-site-with-form?userId=some-id}}.
> User fills some values in form and submits it. Form then validates values but 
> some of them are wrong. User is now redirected to the same page but parameter 
> {{userId=some-id}} is lost.
> I think this should not always throw away all params, in some cases we might 
> want those parameters preserved.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: 
http://jira.magnolia-cms.com/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        


----------------------------------------------------------------
For list details, see: http://www.magnolia-cms.com/community/mailing-lists.html
Alternatively, use our forums: http://forum.magnolia-cms.com/
To unsubscribe, E-mail to: <[email protected]>
----------------------------------------------------------------

Reply via email to