Erlang/OTP Forums

Author Message

<  Ejabberd mailing list  ~  muc logging output

Guest
Posted: Wed Aug 01, 2007 9:35 pm Reply with quote
Guest
It seems that you can insert HTML into your nick:

http://www.jabber.org/muc-logs/jabber@conference.jabber.org/2007-08-01.html#13:03:14

http://www.jabber.org/muc-logs/jabber@conference.jabber.org/2007-08-01.html#13:53:51

Maybe that introduces a potential for spamming the room logs and maybe
it would be better to escape those characters on nick change?

Thanks to elmex for finding this. Smile

Peter

--
Peter Saint-Andre
https://stpeter.im/



Post recived from mailinglist
Guest
Posted: Thu Aug 02, 2007 8:28 am Reply with quote
Guest
2007/8/1, Peter Saint-Andre <stpeter@jabber.org>:
> It seems that you can insert HTML into your nick:
>
> Maybe that introduces a potential for spamming the room logs and maybe
> it would be better to escape those characters on nick change?

Yes. This bug is tracked at:
https://support.process-one.net/browse/EJAB-309

Patch available, and it is 9 characters long Smile

Thanks again to Elmex for explaining how to reproduce.
_______________________________________________
ejabberd mailing list
ejabberd@jabber.ru
http://lists.jabber.ru/mailman/listinfo/ejabberd
Post recived from mailinglist

Display posts from previous:  

All times are GMT
Page 1 of 1
This forum is locked: you cannot post, reply to, or edit topics.

Jump to:  

You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum