https://bugzilla.wikimedia.org/show_bug.cgi?id=19291

Siebrand <[email protected]> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |[email protected]

--- Comment #4 from Siebrand <[email protected]> 2012-10-24 17:31:22 UTC ---
Suggesting WONTFIX here, Niklas. There isn't really a way to find this out. As
long as $context->msg() or wfMessage() is used, even Message::text() and
Message::plain() can be escaped or parsed later on, so there's not really an
indicator.

During the recent updates from wfMsg* to wfMessage, many problems have been
resolved (and some new ones have been introduced, overescaping accidentally),
so the issue of outputting raw HTML should be smaller now, albeit not gone.

>From what I can see, proper auditing on review is the only option for now (and
being warned by users).

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.
You are on the CC list for the bug.

_______________________________________________
Wikibugs-l mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l

Reply via email to