On Thu, Jul 5, 2012 at 7:42 PM, Kevin Falcone <[email protected]> wrote:
> On Thu, Jul 05, 2012 at 12:42:23PM +0200, Carlos Becker wrote:
>> I installed the debian rt4 packages on Debian stable 6.x squeeze.
>> Unfortunately squeeze does not provide rt4 and assettracker packages
>> so I use the packages that are available in debian testing (using apt 
>> pinning).
>>
>> After some tweaks (there were issues with the mysql schema about TYPE=InnoDB 
>> which now must be ENGINE=InnoDB)
>
> If debian is shipping rt4 packages with TYPE=InnoDB that's a bug. RT has
> shipped ENGINE since 4.0.0 and fixed it in 3.8 with 3.8.11.
>
>> basically installation went fine, but again I am getting display problems 
>> with the rt start page.
>> What I see in the front page is the text:
>>
>> <LABEL ACCESSKEY="9"> <SELECT NAME ="Type" 
>> onchange="document.CreateAssetOfType.submit()" class="select-assettype"> 
>> </SELECT> </LABEL>
>> and
>
> Looks like Asset Tracker is pushing HTML into localized strings which
> is something we've discouraged for a long time and disabled in 4.0.6
> because of the massive security holes in the approach. The Asset
> Tracker authors can convert to using l_unsafe but need to make sure
> they're not just introducing security holes.  Best Practical doesn't
> work on Asset Tracker, so you probably want to contact the AT team
> directly.

FYI...this has been resolved, but it hasn't been pushed upstream yet.

https://github.com/rg1/rt-extension-assettracker/commit/c6f0a440358ab3695f692b4aa0eff540bc4cf156

Reply via email to