[Bug 73156] Security review of OOjs UI's PHP implementation

2014-11-20 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=73156 Bartosz Dziewoński matma@gmail.com changed: What|Removed |Added Assignee|cste...@wikimedia.org

[Bug 73156] Security review of OOjs UI's PHP implementation

2014-11-20 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=73156 --- Comment #2 from Gerrit Notification Bot gerritad...@wikimedia.org --- Change 174814 had a related patch set uploaded by Bartosz Dziewoński: LinkTargetInputWidget: Update for #sanitizeValue → #cleanUpValue OOUI change

[Bug 73156] Security review of OOjs UI's PHP implementation

2014-11-20 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=73156 --- Comment #3 from Gerrit Notification Bot gerritad...@wikimedia.org --- Change 174815 had a related patch set uploaded by Bartosz Dziewoński: [BREAKING CHANGE] Rename InputWidget#sanitizeValue → #cleanUpValue

[Bug 73156] Security review of OOjs UI's PHP implementation

2014-11-20 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=73156 Gerrit Notification Bot gerritad...@wikimedia.org changed: What|Removed |Added Status|NEW

[Bug 73156] Security review of OOjs UI's PHP implementation

2014-11-20 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=73156 --- Comment #4 from Gerrit Notification Bot gerritad...@wikimedia.org --- Change 174835 had a related patch set uploaded by Bartosz Dziewoński: PHP: Reject malformed and potentially evil input when outputting HTML

[Bug 73156] Security review of OOjs UI's PHP implementation

2014-11-20 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=73156 --- Comment #5 from Bartosz Dziewoński matma@gmail.com --- (In reply to Chris Steipp from comment #0) The only thing I'd really like to see changed is in php/widgets/InputWidget.php, the sanitizeValue function doesn't do any (security)

[Bug 73156] Security review of OOjs UI's PHP implementation

2014-11-20 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=73156 --- Comment #6 from Gerrit Notification Bot gerritad...@wikimedia.org --- Change 174844 had a related patch set uploaded by Bartosz Dziewoński: LabelElement: Kill inline styles https://gerrit.wikimedia.org/r/174844 -- You are receiving this

[Bug 73156] Security review of OOjs UI's PHP implementation

2014-11-07 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=73156 Krinkle krinklem...@gmail.com changed: What|Removed |Added CC||krinklem...@gmail.com