Uploaded image for project: 'Kudu'
  1. Kudu
  2. KUDU-1898

/varz page doesn't HTML-escape flag values

    XMLWordPrintableJSON

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 1.3.0
    • Fix Version/s: 1.3.0
    • Component/s: util
    • Labels:
      None

      Description

      I was just trying the new "flag redaction" feature and noticed that the string '<redacted>' isn't getting properly HTML-escaped in the /varz web page. It appears we've never properly escaped flag values in this context, but it's only obvious now that the '<redacted>' string is getting interpreted as an HTML tag.

        Attachments

          Activity

            People

            • Assignee:
              hahao Hao Hao
              Reporter:
              tlipcon Todd Lipcon
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: