Demo Discussion
Forum Config Examples Contributions Vulnerabilities
  Discussion forum about ELOG, Page 624 of 807  Not logged in ELOG logo
ID Date Icon Author Author Email Categorydown OS ELOG Version Subject
  1285   Wed Jul 20 21:43:56 2005 Reply Stefan Rittstefan.ritt@psi.chBug reportAll Re: [code] should be a sort of <CDATA >

Emiliano Gabrielli wrote:
Using the [code] elocode should be intended also to preserve the tagged text from beeing parsed as html or elcode itself ..

this is an example:

Quote:
Note that, for security reasons, you should check the MD5 FINGERPRINT of the SSL certificate issued by the server agaist the following one:

MD5 Fingerprint = 23:A7:AD:33:3C:08:BE:2A:62:6E:85:DF:B8:00:23:40


Thank you


As you can see, your entry with the [code] section is now shown without interpretation. So everything between [code] and [/code] is not interpreted as ELCode tags. The modification is committed to CVS.
  1286   Wed Jul 20 22:28:14 2005 Reply Stefan Rittstefan.ritt@psi.chBug reportLinuxrev 1.703Re: Display Subject and HTML tags, regression

Emiliano Gabrielli wrote:
rev 1.703 makes the following code not to work:
Display Subject               = <b>$subject</b>

the <b> tag is displayed and not interpreted, as it was in previous revisions..


rev. 1.707 makes it work again Big grin
  1287   Wed Jul 20 22:39:05 2005 Reply Stefan Rittstefan.ritt@psi.chBug reportLinuxrev 1.703Re: Display Subject and HTML tags, regression

Emiliano Gabrielli wrote:

Emiliano Gabrielli wrote:
rev 1.703 makes the following code not to work:
Display Subject               = <b>$subject</b>

the <b> tag is displayed and not interpreted, as it was in previous revisions..


this patch should fix the problem .. a little bug still remain, if you insert some allowed HTML tags in the subject this is detected by is_html() so the Display Attribute and the Link is not applied .. the result is that the HTML is working but no elog featur is applied


Your line
if (p && strchr(str, '>') && p >= str && *(p-1) != '\\')

in the code does not work. If the pattern is at the beginning of the string (p == str), then (p-1) points to an invalid location and can cause a segmentation fault. The correct patch is in CVS.
  1292   Thu Jul 21 10:59:22 2005 Reply Emiliano GabrielliAlberT@SuperAlberT.itBug reportAll Re: [code] should be a sort of <CDATA >

Stefan Ritt wrote:

Emiliano Gabrielli wrote:
Using the [code] elocode should be intended also to preserve the tagged text from beeing parsed as html or elcode itself ..

this is an example:

Quote:
Note that, for security reasons, you should check the MD5 FINGERPRINT of the SSL certificate issued by the server agaist the following one:

MD5 Fingerprint = 23:A7:AD:33:3C:08:BE:2A:62:6E:85:DF:B8:00:23:40


Thank you


As you can see, your entry with the [code] section is now shown without interpretation. So everything between [code] and [/code] is not interpreted as ELCode tags. The modification is committed to CVS.


thanks Smile
  1293   Thu Jul 21 11:00:47 2005 Reply Emiliano GabrielliAlberT@SuperAlberT.itBug reportLinuxrev 1.703Re: Display Subject and HTML tags, regression

Stefan Ritt wrote:

Emiliano Gabrielli wrote:
rev 1.703 makes the following code not to work:
Display Subject               = <b>$subject</b>

the <b> tag is displayed and not interpreted, as it was in previous revisions..


rev. 1.707 makes it work again Big grin


ok, nice Smile
  1294   Thu Jul 21 11:02:44 2005 Reply Emiliano GabrielliAlberT@SuperAlberT.itBug reportLinuxrev 1.703Re: Display Subject and HTML tags, regression

Stefan Ritt wrote:

Emiliano Gabrielli wrote:

Emiliano Gabrielli wrote:
rev 1.703 makes the following code not to work:
Display Subject               = <b>$subject</b>

the <b> tag is displayed and not interpreted, as it was in previous revisions..


this patch should fix the problem .. a little bug still remain, if you insert some allowed HTML tags in the subject this is detected by is_html() so the Display Attribute and the Link is not applied .. the result is that the HTML is working but no elog featur is applied


Your line
if (p && strchr(str, '>') && p >= str && *(p-1) != '\\')

in the code does not work. If the pattern is at the beginning of the string (p == str), then (p-1) points to an invalid location and can cause a segmentation fault. The correct patch is in CVS.


ehhe, I used "should" infact Tongue
  1304   Sat Jul 23 16:45:28 2005 Reply Emiliano GabrielliAlberT@SuperAlberT.itBug reportAll Re: <img> in Display Attribute

Stefan Ritt wrote:

BTW: Conditional attributes now also work for email notifications, so you can do for example:
Attributes = Author, Category, Email encoding, Subject
Options Email encoding = plain{1}, HTML{2}
{1} Email encoding = 1
{2} Email encoding = 2


if one uses ROptions instead of a simple Options the text displaied is "plain{1}" (with the "{1}" not stripped out!!)
  1306   Sat Jul 23 18:30:57 2005 Reply Stefan Rittstefan.ritt@psi.chBug reportAll Re: <img> in Display Attribute

Emiliano Gabrielli wrote:
if one uses ROptions instead of a simple Options the text displaied is "plain{1}" (with the "{1}" not stripped out!!)


Ok, fixed.
ELOG V3.1.5-3fb85fa6