Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-16978

The rendered diff is executed even when only accessing the content diff

    XMLWordPrintable

    Details

    • Difficulty:
      Unknown
    • Documentation:
      N/A
    • Documentation in Release Notes:
      N/A
    • Similar issues:

      Description

      The rendered diff is executing the content which can be dangerous so at the very least it should be on demand and not executed every time the diff UI shows up (UI in which the rendered diff is hidden by default).

      For example if the content contain something like a sendRedirect it makes impossible to access the diff which is quite annoying...

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              mflorea Marius Dumitru Florea
              Reporter:
              tmortagne Thomas Mortagne
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:
                Date of First Response: