Details
-
Bug
-
Resolution: Fixed
-
Blocker
-
11.6-rc-1
-
Unknown
-
N/A
-
N/A
-
Description
The rendered diff is executing the content which can be dangerous so at the very least it should be on demand and not executed every time the diff UI shows up (UI in which the rendered diff is hidden by default).
For example if the content contain something like a sendRedirect it makes impossible to access the diff which is quite annoying...
Attachments
Issue Links
- is related to
-
XWIKI-13445 Provide an HTML visual diff
- Closed
- relates to
-
XWIKI-17043 Compare versions shows "From" instead of "To"
- Closed