From mboxrd@z Thu Jan 1 00:00:00 1970 From: Adolf Belka To: development@lists.ipfire.org Subject: Re: [PATCH] connscheduler.cgi: Remove cleanhtml command from Remark Date: Wed, 06 Mar 2024 23:23:45 +0100 Message-ID: <55e772fb-9252-438a-a7a3-af634ac16426@ipfire.org> In-Reply-To: <666E110C-A2EB-4BAE-9D93-44E80DBD4C00@ipfire.org> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============0427450628972917693==" List-Id: --===============0427450628972917693== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Hi Michael, On 06/03/2024 22:28, Michael Tremer wrote: > Hello Adolf, >=20 > I believe that I cannot merge these patches. Then you need to also look back at the dns.cgi patch for the bug fix due=20 to german umlauts being changed. The acceptance of that patch is what=20 made me create these patches as they all had the same problem with=20 remarks as well. If this can't be accepted as is then that patch needs=20 to be reverted. https://git.ipfire.org/?p=3Dipfire-2.x.git;a=3Dcommit;h=3D7c6ff5ff12331a53f41= 6080a44c8d6145e78bfac >=20 > The reason simply is that it would create a store cross-site scripting atta= ck vector because someone could store some