Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 201878 - dev-php/stringparser_bbcode-0.3.2a version bump and license change
Summary: dev-php/stringparser_bbcode-0.3.2a version bump and license change
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: PHP Bugs
URL: http://christian-seiler.de/projekte/p...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-12-10 19:12 UTC by Jan Rieger
Modified: 2007-12-15 13:28 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
dev-php/stringparser_bbcode-0.3.2a.ebuild (stringparser_bbcode-0.3.2a.ebuild,728 bytes, text/plain)
2007-12-10 19:13 UTC, Jan Rieger
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Jan Rieger 2007-12-10 19:12:06 UTC
* Several bugfixes:
	* fixed bug in handling of case insensitive codes,
	* fixed nasty bug that made [list][*][*][/list] misbehave
	* Documentation: Changed example to prevent XSS attacks
* Changed license from "Artistic-2 or GPL-2" to "MIT".

Reproducible: Always
Comment 1 Jan Rieger 2007-12-10 19:13:22 UTC
Created attachment 138190 [details]
dev-php/stringparser_bbcode-0.3.2a.ebuild

Ebuild for dev-php/stringparser_bbcode-0.3.2a
Comment 2 Jakub Moc (RETIRED) gentoo-dev 2007-12-10 20:04:36 UTC
(In reply to comment #0)
> * Documentation: Changed example to prevent XSS attacks

What kind of example are you referring to here? There's no .php example files shipped with the ebuild.

Comment 3 Christian Seiler 2007-12-10 20:55:15 UTC
I'm the developer of the package (Jan sent me the link to this bug report).

The example I meant in the ChangeLog is inside the documentation, have a look at the following web page:
http://www.christian-seiler.de/projekte/php/bbcode/doc/en/chapter9.php
(that page is also available inside the tarball, stringparser_bbcode-0.3.2a/doc/en/chapter9.html)

I added checks to the functions that make sure that the file, data, javascript and jar protocols can't be used in links or images so that people who just C&P the code into their own projects without reading the whole documentation (chapter 4 especially) aren't vulnerable to XSS attacks.
Comment 4 Jakub Moc (RETIRED) gentoo-dev 2007-12-15 13:28:56 UTC
InCVS, thanks.