HTML Tags in Page Titles Should Be Escaped in Admin Interface
-------------------------------------------------------------

                 Key: MAGNOLIA-1897
                 URL: http://jira.magnolia.info/browse/MAGNOLIA-1897
             Project: Magnolia
          Issue Type: Bug
          Components: admininterface
    Affects Versions: 3.0.5
         Environment: All
            Reporter: Sean McMains
         Assigned To: Philipp Bracher
            Priority: Minor


If one enters HTML tags as part of a Page Title, and then views the page 
hierarchy in AdminCentral, those HTML tags are interpreted, which can mess up 
rendering of the AdminConsole. (For example, try putting a few "<br/>" tags in 
a page title.)

The same issue applies to the "Full Role Name" field in Roles, the "Full Group 
Name" field in Groups, and the "Full Name" field in Users.

To reproduce:

1. Enter "page<br/>name<br/>test" for a page name in AdminConsole
2. Press the "refresh button"

Expected result:

The page name would display as entered.

Actual result:

The page name is spread across 3 lines and overlaps any items below it.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: 
http://jira.magnolia.info/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

----------------------------------------------------------------
for list details see
http://documentation.magnolia.info/docs/en/editor/stayupdated.html
----------------------------------------------------------------

Reply via email to