Commit 4d1c399f authored by Matt Selsky's avatar Matt Selsky Committed by Gervase Markham

Bug 1102842 - remove and/or unwhitelist unsafe filters. r=gerv, a=simon.

parent 7b8a5d16
...@@ -759,35 +759,6 @@ sub create { ...@@ -759,35 +759,6 @@ sub create {
# built-in filter, please also add a stub filter to t/004template.t. # built-in filter, please also add a stub filter to t/004template.t.
FILTERS => { FILTERS => {
# Render text in required style.
inactive => [
sub {
my($context, $isinactive) = @_;
return sub {
return $isinactive ? '<span class="bz_inactive">'.$_[0].'</span>' : $_[0];
}
}, 1
],
closed => [
sub {
my($context, $isclosed) = @_;
return sub {
return $isclosed ? '<span class="bz_closed">'.$_[0].'</span>' : $_[0];
}
}, 1
],
obsolete => [
sub {
my($context, $isobsolete) = @_;
return sub {
return $isobsolete ? '<span class="bz_obsolete">'.$_[0].'</span>' : $_[0];
}
}, 1
],
# Returns the text with backslashes, single/double quotes, # Returns the text with backslashes, single/double quotes,
# and newlines/carriage returns escaped for use in JS strings. # and newlines/carriage returns escaped for use in JS strings.
js => sub { js => sub {
......
...@@ -74,9 +74,6 @@ foreach my $include_path (@include_paths) { ...@@ -74,9 +74,6 @@ foreach my $include_path (@include_paths) {
no_break => sub { return $_; } , no_break => sub { return $_; } ,
js => sub { return $_ } , js => sub { return $_ } ,
base64 => sub { return $_ } , base64 => sub { return $_ } ,
inactive => [ sub { return sub { return $_; } }, 1] ,
closed => [ sub { return sub { return $_; } }, 1] ,
obsolete => [ sub { return sub { return $_; } }, 1] ,
url_quote => sub { return $_ } , url_quote => sub { return $_ } ,
css_class_quote => sub { return $_ } , css_class_quote => sub { return $_ } ,
xml => sub { return $_ } , xml => sub { return $_ } ,
......
...@@ -210,9 +210,9 @@ sub directive_ok { ...@@ -210,9 +210,9 @@ sub directive_ok {
# Note: If a single directive prints two things, and only one is # Note: If a single directive prints two things, and only one is
# filtered, we may not catch that case. # filtered, we may not catch that case.
return 1 if $directive =~ /FILTER\ (html|csv|js|base64|css_class_quote|ics| return 1 if $directive =~ /FILTER\ (html|csv|js|base64|css_class_quote|ics|
quoteUrls|time|uri|xml|lower|html_light| quoteUrls|time|uri|xml|html_light|
obsolete|inactive|closed|unitconvert| unitconvert|txt|html_linebreak|markdown|
txt|html_linebreak|markdown|none|null)\b/x; none|null)\b/x;
return 0; return 0;
} }
......
...@@ -68,7 +68,7 @@ ...@@ -68,7 +68,7 @@
[% IF changes_saved %] [% IF changes_saved %]
<div id="message"> <div id="message">
The changes to your [% current_tab.label FILTER lower %] have been saved. The changes to your [% current_tab.label FILTER lower FILTER html %] have been saved.
[% IF email_changes_saved %] [% IF email_changes_saved %]
<p> <p>
......
...@@ -70,7 +70,15 @@ function toggle_display(link) { ...@@ -70,7 +70,15 @@ function toggle_display(link) {
<a href="attachment.cgi?id=[% attachment.id %]" <a href="attachment.cgi?id=[% attachment.id %]"
title="View the content of the attachment"> title="View the content of the attachment">
[% END %] [% END %]
<b>[% attachment.description FILTER html FILTER obsolete(attachment.isobsolete) %]</b> <b>
[% IF attachment.isobsolete %]
<span class="bz_obsolete">
[% END %]
[% attachment.description FILTER html %]
[% IF attachment.isobsolete %]
</span>
[% END %]
</b>
[% "</a>" IF attachment.datasize %] [% "</a>" IF attachment.datasize %]
<span class="bz_attach_extra_info"> <span class="bz_attach_extra_info">
......
...@@ -34,7 +34,15 @@ ...@@ -34,7 +34,15 @@
<th colspan="6" class="bz_attach_footer">Attachment #[% a.id %]</th> <th colspan="6" class="bz_attach_footer">Attachment #[% a.id %]</th>
</tr> </tr>
<tr> <tr>
<td>[% a.description FILTER html FILTER obsolete(a.isobsolete) %]</td> <td>
[% IF a.isobsolete %]
<span class="bz_obsolete">
[% END %]
[% a.description FILTER html %]
[% IF a.isobsolete %]
</span>
[% END %]
</td>
<td> <td>
[% IF a.ispatch %] [% IF a.ispatch %]
......
...@@ -136,7 +136,9 @@ ...@@ -136,7 +136,9 @@
[% BLOCK buglink %] [% BLOCK buglink %]
[% isclosed = !bug.isopened %] [% isclosed = !bug.isopened %]
[% FILTER closed(isclosed) -%] [% IF isclosed %]
<span class="bz_closed">
[% END %]
<a title="[% INCLUDE buginfo bug=bug %]" <a title="[% INCLUDE buginfo bug=bug %]"
href="show_bug.cgi?id=[% bugid %]"> href="show_bug.cgi?id=[% bugid %]">
<b>[%- bugid %]:</b> <b>[%- bugid %]:</b>
...@@ -148,6 +150,8 @@ ...@@ -148,6 +150,8 @@
<img src="skins/standard/dependency-tree/tree.png" <img src="skins/standard/dependency-tree/tree.png"
title="See dependency tree for [% terms.bug %] [%+ bugid FILTER html %]"> title="See dependency tree for [% terms.bug %] [%+ bugid FILTER html %]">
</a> </a>
[% IF isclosed %]
</span>
[% END %] [% END %]
[% END %] [% END %]
......
...@@ -31,7 +31,7 @@ ...@@ -31,7 +31,7 @@
[% FOREACH column = columns.keys %] [% FOREACH column = columns.keys %]
[% NEXT IF collist.contains(column) %] [% NEXT IF collist.contains(column) %]
[%# We lowecase the keys so that the sort happens case-insensitively. %] [%# We lowecase the keys so that the sort happens case-insensitively. %]
[% SET column_desc = field_descs.$column || column FILTER lower %] [% SET column_desc = field_descs.$column || column FILTER lower FILTER html %]
[% available_columns.$column_desc = column %] [% available_columns.$column_desc = column %]
[% END %] [% END %]
......
...@@ -371,7 +371,13 @@ ...@@ -371,7 +371,13 @@
<td> <td>
[% SET inactive = !group.is_active %] [% SET inactive = !group.is_active %]
[% group.description FILTER html_light FILTER inactive(inactive) %] [% IF inactive %]
<span class="bz_inactive">
[% END %]
[% group.description FILTER html_light %]
[% IF inactive %]
</span>
[% END %]
</td> </td>
</tr> </tr>
...@@ -380,8 +386,8 @@ ...@@ -380,8 +386,8 @@
</table> </table>
[% IF foundinactive %] [% IF foundinactive %]
<p class="bz_info">(Note: [% terms.Bugs %] may not be added to [% FILTER inactive %]inactive <p class="bz_info">(Note: [% terms.Bugs %] may not be added to inactive
groups[% END %], only removed.)</p> groups, only removed.)</p>
[% END %] [% END %]
[% END %] [% END %]
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment