Bug 724481 (BRMS-426)

Summary: Atom feeds need to escape XML special characters
Product: [JBoss] JBoss Enterprise BRMS Platform 5 Reporter: Jiri Locker <jlocker>
Component: BRM (Guvnor)Assignee: Tihomir Surdilovic <tsurdilo>
Status: CLOSED NEXTRELEASE QA Contact:
Severity: unspecified Docs Contact:
Priority: high    
Version: 5.1.0.ER3   
Target Milestone: ---   
Target Release: 5.1.0.ER4   
Hardware: Unspecified   
OS: Unspecified   
URL: http://jira.jboss.org/jira/browse/BRMS-426
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2010-11-24 09:18:42 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Jiri Locker 2010-11-03 20:55:38 UTC
securitylevel_name: Public

For examaple posting a comment that looks like "evil comment</feed>" into an asset's discussion breaks the feed XML document.
Something similar to http://commons.apache.org/lang/api-release/org/apache/commons/lang/StringEscapeUtils.html#escapeXml%28java.lang.String%29 will be necessary to apply to the user input before building the feed XML.

Comment 1 Jiri Locker 2010-11-03 20:56:42 UTC
Link: Added: This issue depends BRMS-382


Comment 2 Jiri Locker 2010-11-03 20:58:05 UTC
Link: Removed: This issue depends BRMS-382 


Comment 3 Jiri Locker 2010-11-03 20:58:31 UTC
Link: Added: This issue is related to BRMS-382


Comment 4 Jiri Locker 2010-11-04 21:01:15 UTC
Link: Added: This issue is related to BRMS-391


Comment 5 Jiri Locker 2010-11-04 21:19:15 UTC
Please also make sure that special characters are encoded when submitting a comment. User might want to describe conditions with expressions using <, >, &, etc. For instance, "The condition should be a<b and b>c." which doesn't work now because the substring "<b and b>" is handled as an HTML tag.

Comment 6 Tihomir Surdilovic 2010-11-05 20:56:31 UTC
Link: Added: This issue depends GUVNOR-1087


Comment 7 Jiri Locker 2010-11-09 14:23:28 UTC
Link: Added: This issue is a dependency of JBQA-3766


Comment 8 Jiri Locker 2010-11-16 17:51:55 UTC
Link: Added: This issue is related to BRMS-443


Comment 9 Jiri Locker 2010-11-24 09:24:26 UTC
Link: Added: This issue is related to BRMS-452