Syllabus does not remove bad tags after first post

Description

1) Login as instructor go to course go to Syllabus

2) Post evil HTML: <p evil="true">test</p>

3) Click Post

Here is error:

Error: The p tag contained an attribute that we could not process. The evil attribute has been filtered out, but the tag is still in place. The value of the attribute was "true".

But this is not true.... the evil attribute has not been filtered out. The syllabus tool is not replacing the user-entered HTML with the cleaned HTML. It is forcing the user to manually clean the HTML before proceeding. Every other tool in Sakai replaces the user-entered HTML with cleaned HTML.

Activity

Show:

Sam Ottenhoff June 11, 2013 at 5:15 PM

2.9.x r125641

Sam Ottenhoff May 15, 2013 at 1:52 PM

Trunk r124127

Fixed

Details

Priority

Affects versions

Fix versions

Components

Assignee

Reporter

Environment

Trunk with AntiSamy on high

Created May 15, 2013 at 1:19 PM
Updated September 17, 2013 at 11:53 AM
Resolved May 15, 2013 at 1:52 PM