git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [BUG] gitweb: XSS vulnerability of RSS feed

From
Kevin <ikke@ikke.info>
Date
Nov 13, 2012, 15:45 UTC
Message-ID
<CAO54GHCzeWv41Bu5By0JOzbBHGuzXV=krdDr0U=QsMBun7PF7A@mail.gmail.com>
In-Reply-To
<CAM9Z-nkuHj8MWLfWsvY=EqHXCUS+Pk5Ezv6m5J+cnh7cQHNc_g@mail.gmail.com>

The problem with input filtering is that you can only filter for one output scenario. What if the the input is going to be output in a wiki like environment, or to pdf, or whatever? Then you have to unescape the data again, and maybe apply filtering/escaping for those environments.

You only know how to escape data when you are going to output it, so then is the the best moment to escape it.

Previous: Jakub NarębskiNext: Jakub Narębski
Message 10 of 15 in “[BUG] gitweb: XSS vulnerability of RSS feed”
  1. glpk xypronNov 11, 2012
  2. Drew NorthupNov 12, 2012
  3. Jeff KingNov 12, 2012
  4. Jeff KingNov 12, 2012
  5. Junio C HamanoNov 12, 2012
  6. Jakub NarębskiNov 12, 2012
  7. Jeff KingNov 12, 2012
  8. Drew NorthupNov 13, 2012
  9. Jakub NarębskiNov 13, 2012
  10. KevinNov 13, 2012
  11. Jakub NarębskiNov 13, 2012
  12. Jeff KingNov 13, 2012
  13. Jakub NarębskiNov 13, 2012
  14. Andreas SchwabNov 12, 2012
  15. Pyeron, Jason J CTR (US)Nov 13, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.