[ 
https://issues.apache.org/jira/browse/SLING-4231?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14240269#comment-14240269
 ] 

Radu Cotescu edited comment on SLING-4231 at 12/9/14 11:21 PM:
---------------------------------------------------------------

The attached patch ([^SLING-4231.patch]) adds the {{<ul>}} tag in the 
{{XSSRuntimeExtension}}'s whitelist.


was (Author: radu.cotescu):
The attached patch adds the {{<ul>}} tag in the {{XSSRuntimeExtension}}'s 
whitelist.

> [Sightly] The XSSRuntimeExtension should not escape the "ul" tag for element 
> names
> ----------------------------------------------------------------------------------
>
>                 Key: SLING-4231
>                 URL: https://issues.apache.org/jira/browse/SLING-4231
>             Project: Sling
>          Issue Type: Bug
>          Components: Scripting
>            Reporter: Radu Cotescu
>             Fix For: Scripting Sightly Engine 1.0.0
>
>         Attachments: SLING-4231.patch
>
>
> The {{XSSRuntimeExtension}} should not escape the {{ul}} tag for element 
> names, given that {{dl}} and {{ol}} are allowed.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to