if (! length $stylesheet) {
return "[[meta ".gettext("stylesheet not found")."]]";
}
- push @{$metaheaders{$page}}, '<link href="'.urlto($stylesheet, $page).
+ push @{$metaheaders{$page}}, scrub('<link href="'.urlto($stylesheet, $page).
'" rel="'.encode_entities($rel).
'" title="'.encode_entities($title).
- "\" type=\"text/css\" />";
+ "\" type=\"text/css\" />");
}
elsif ($key eq 'openid') {
if (exists $params{server} && safeurl($params{server})) {
+ikiwiki (2.53.6) oldstable-security; urgency=low
+
+ * meta: Security fix; don't allow alternative stylesheets to be added on
+ pages where the htmlscrubber is enabled.
+
+ -- Joey Hess <joeyh@debian.org> Mon, 28 Mar 2011 12:35:13 -0400
+
ikiwiki (2.53.5) stable-security; urgency=high
* htmlscrubber: Security fix: In data:image/* uris, only allow a few