Last modified: 2009-07-05 11:58:00 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T21517, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 19517 - Page titles in Special:Contributions are not HTML-escaped
Page titles in Special:Contributions are not HTML-escaped
Status: RESOLVED FIXED
Product: MediaWiki
Classification: Unclassified
Interface (Other open bugs)
unspecified
All All
: Normal enhancement (vote)
: ---
Assigned To: Nobody - You can work on this!
http://en.wikipedia.org/w/index.php?t...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2009-07-04 16:34 UTC by Amalthea
Modified: 2009-07-05 11:58 UTC (History)
1 user (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Amalthea 2009-07-04 16:34:19 UTC
See the URL above. For testing purposes I created the account »Amalthea'"&amp;lt« and found that browsers "fixed" the broken html entity "&amp;lt" and displayed a "<" instead - see the URL above. Apparently the ampersand isn't escaped correctly on the contributions page, Special:RecentPages didn't have that problem.

Fun could probably be had with some of the more disruptive entities. I don't know if there's a HTML entity for the U+202E RIGHT-TO-LEFT OVERRIDE, but if so, then &#x202e; this could be abused for some comedic effect.
Comment 1 Amalthea 2009-07-04 16:37:28 UTC
Hmm, I thought HTML entities would be passed through here like in MediaWiki, but apparently not. Read the above as: account name » Amalthea'"&lt «, browsers display "&lt" as "<", and the comedic effect in the last paragraph fell flat.
Comment 2 Niklas Laxström 2009-07-05 11:58:00 UTC
Fixed in r52521.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links