Hide Forgot
securitylevel_name: Public For examaple posting a comment that looks like "evil comment</feed>" into an asset's discussion breaks the feed XML document. Something similar to http://commons.apache.org/lang/api-release/org/apache/commons/lang/StringEscapeUtils.html#escapeXml%28java.lang.String%29 will be necessary to apply to the user input before building the feed XML.
Link: Added: This issue depends BRMS-382
Link: Removed: This issue depends BRMS-382
Link: Added: This issue is related to BRMS-382
Link: Added: This issue is related to BRMS-391
Please also make sure that special characters are encoded when submitting a comment. User might want to describe conditions with expressions using <, >, &, etc. For instance, "The condition should be a<b and b>c." which doesn't work now because the substring "<b and b>" is handled as an HTML tag.
Link: Added: This issue depends GUVNOR-1087
Link: Added: This issue is a dependency of JBQA-3766
Link: Added: This issue is related to BRMS-443
Link: Added: This issue is related to BRMS-452