- π¬π§United Kingdom steven jones
Yeah, this one is a tricky one eh?
Because...you're essentially saying that everything that got token replaced is now considered 'safe' which then probably opens up a decent amount of attack surface. As in, yes, you can now add inline style attributes, but presumably you could also add in JavaScript etc.
I'm not sure that message can know one way or the other, but this patch does at least return message to functioning as it did in Drupal 7.
I'm going to leave this as needs review, because as I've mentioned, I'm not sure if there's a good way to go here.
I suppose maybe Message sort of accepts that there might be attacks via the message channels / if someone puts in tokens that are exploitable, then that's user error.
- π¨π¦Canada joseph.olstad
I've also noticed this, going to try the patch.
- Merge request !41Issue #3183734 by guillaumeg, joseph.olstad: Unable to use inline styles when... β (Open) created by joseph.olstad
- First commit to issue fork.
- πΊπΈUnited States bluegeek9
bluegeek9 β changed the visibility of the branch 8.x-1.x to hidden.