https://bugzilla.wikimedia.org/show_bug.cgi?id=14779





--- Comment #3 from Brion Vibber <[email protected]>  2009-01-04 03:32:21 UTC 
---
Sanitizer::decodeCharReferences *must not* attempt to deal with URL
percent-encoding, as that would cause corruption of totally unrelated HTML
output.

Probably the Sanitizer::decodeCharReferences() and the %-check & urldecode()
both belong in either Title:newFromText or directly into
Title::secureAndSplit() to ensure that titles are being consistently handled at
the low-level; this means the various checks at higher levels should be checked
and mostly pulled out.

There are probably a number of related bugs still open on this issue; be good
to make sure they're all tied together.


-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.
You are on the CC list for the bug.

_______________________________________________
Wikibugs-l mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l

Reply via email to