Bug 987909 - Org names rendered as HTML
Summary: Org names rendered as HTML
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Subscription Asset Manager
Classification: Retired
Component: katello
Version: 1.3
Hardware: Unspecified
OS: Unspecified
unspecified
urgent
Target Milestone: rc
: ---
Assignee: Adam Price
QA Contact: Tazim Kolhar
URL:
Whiteboard:
Depends On:
Blocks: sam13-tracker 995936
TreeView+ depends on / blocked
 
Reported: 2013-07-24 12:03 UTC by Jeff Weiss
Modified: 2016-04-26 00:55 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
: 995936 (view as bug list)
Environment:
Last Closed: 2013-10-01 11:14:23 UTC
Embargoed:
jweiss: automate_bug+


Attachments (Terms of Use)
Org Created not rendered as HTML tags (69.92 KB, image/png)
2013-08-12 13:32 UTC, Tazim Kolhar
no flags Details


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHEA-2013:1390 0 normal SHIPPED_LIVE Release 1.3 of Subscription Asset Manager 2013-10-01 14:43:14 UTC

Description Jeff Weiss 2013-07-24 12:03:58 UTC
Description of problem:


Version-Release number of selected component (if applicable):
1.4.2-1.git.961.e5d1bd2.el6

How reproducible:


Steps to Reproduce:
1. Create org called "<a href='foo'>Click here</a>"
2.
3.

Actual results:
org created, notification displayed with "Click here" link that actually points at 'foo'.

Expected results:
Validation fail

Additional info:

Comment 2 Jeff Weiss 2013-07-24 12:44:27 UTC
Note, the Expected Result should be
Notification displayed with org name escaped

Comment 3 Adam Price 2013-07-24 22:08:43 UTC
https://github.com/Katello/katello/pull/2680

Comment 4 Bryan Kearney 2013-08-02 18:52:09 UTC
SNAP0 contains these bug fixes. Moving to ON_QA.

Comment 7 Tazim Kolhar 2013-08-12 13:32:49 UTC
Created attachment 785685 [details]
Org Created not rendered as HTML tags

VERIFIED :

# rpm -qa | grep katello
katello-selinux-1.4.4-2.el6sat.noarch
katello-candlepin-cert-key-pair-1.0-1.noarch
katello-certs-tools-1.4.2-2.el6sat.noarch
katello-cli-common-1.4.3-5.el6sat.noarch
katello-cli-1.4.3-5.el6sat.noarch
katello-common-1.4.3-6.el6sam_splice.noarch
katello-configure-1.4.4-2.el6sat.noarch
katello-glue-elasticsearch-1.4.3-6.el6sam_splice.noarch
katello-headpin-all-1.4.3-6.el6sam_splice.noarch
katello-glue-candlepin-1.4.3-6.el6sam_splice.noarch
signo-katello-0.0.10-2.el6sat.noarch
katello-headpin-1.4.3-6.el6sam_splice.noarch

Comment 9 errata-xmlrpc 2013-10-01 11:14:23 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHEA-2013-1390.html


Note You need to log in before you can comment on or make changes to this bug.