Uploaded image for project: 'Wicket'
  1. Wicket
  2. WICKET-4219

Enable markup escaping of WizardStep's labels by default due to security aspects

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 1.4.19, 1.5.3
    • 6.0.0-beta2
    • wicket-extensions
    • None

    Description

      Markup escaping of the title and summary label in org.apache.wicket.extensions.wizard.WizardStep are disabled by default. This fact is not documented, an therefore there could be some security risk, when their Models are generated from user input.
      An improvement would be to enable markup escaping and let the user disable this on demand.

      Attachments

        Activity

          People

            svenmeier Sven Meier
            aul Thomas Aulinger
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: