Uploaded image for project: 'OFBiz'
  1. OFBiz
  2. OFBIZ-12691

Extend HTML Sanitizer - style attribute

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • Upcoming Branch
    • 22.01.01
    • content
    • None

    Description

      Right now it is not possible to assign inline style to html content. Trumbowyg Editor uses such tags for align paragraphs.

      style="text-align:right"

      It is necessary to remove space within the attribute and remove the trailing semicolon in order to apply with OWASP filter rules.

      Create or open content with "Long text". Goto dataresource and edit HTML. Put in some text and use the align icons (right, center ...) to format the text. Save. You will get a security info.

      Attachments

        1. SanitizerStyle.patch
          2 kB
          Ingo Wolfmayr

        Activity

          People

            jleroux Jacques Le Roux
            iwolf Ingo Wolfmayr
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: