Files
gitlabhq/features/steps/project
Robert Speicher 7cc239528e Remove persistent XSS vulnerability in commit_person_link helper
Because we were incorrectly supplying the tooltip title as
`data-original-title` (which Bootstrap's Tooltip JS automatically
applies based on the `title` attribute; we should never be setting it
directly), the value was being passed through as-is.

Instead, we should be supplying the normal `title` attribute and letting
Rails escape the value, which also negates the need for us to call
`sanitize` on it.

Closes https://gitlab.com/gitlab-org/gitlab-ce/issues/15126
2016-04-17 18:42:49 -04:00
..
2016-04-11 09:43:59 +01:00
2016-04-06 12:52:07 +01:00
2016-03-10 14:48:29 -05:00
2015-10-03 19:59:54 -05:00
2015-12-18 14:19:48 -06:00
2016-03-04 10:44:04 +00:00
2015-12-23 12:26:50 -05:00