]> git.vanrenterghem.biz Git - git.ikiwiki.info.git/commitdiff
meta: Security fix; don't allow alternative stylesheets to be added on pages where...
authorJoey Hess <joey@kitenet.net>
Mon, 28 Mar 2011 16:38:46 +0000 (12:38 -0400)
committerJoey Hess <joey@kitenet.net>
Mon, 28 Mar 2011 16:38:46 +0000 (12:38 -0400)
IkiWiki/Plugin/meta.pm
debian/changelog

index eccbf976c6a7e368966b13801ef1ab3b53a4cce8..c33c8b23882f7e23c8114d67c7ecd388666475e3 100644 (file)
@@ -173,10 +173,10 @@ sub preprocess (@) {
                if (! length $stylesheet) {
                        error gettext("stylesheet not found")
                }
-               push @{$metaheaders{$page}}, '<link href="'.urlto($stylesheet, $page).
+               push @{$metaheaders{$page}}, scrub('<link href="'.urlto($stylesheet, $page).
                        '" rel="'.encode_entities($rel).
                        '" title="'.encode_entities($title).
-                       "\" type=\"text/css\" />";
+                       "\" type=\"text/css\" />", $page, $destpage);
        }
        elsif ($key eq 'openid') {
                my $delegate=0; # both by default
index b4d502d009e12fed9d765b4c23d0c2aa15015006..900f6a98412bea3ad3450648cd02ad505748ed5e 100644 (file)
@@ -1,3 +1,10 @@
+ikiwiki (3.20100815.7) stable-security; urgency=high
+
+  * meta: Security fix; don't allow alternative stylesheets to be added on
+    pages where the htmlscrubber is enabled.
+
+ -- Joey Hess <joeyh@debian.org>  Mon, 28 Mar 2011 12:35:13 -0400
+
 ikiwiki (3.20100815.6) testing; urgency=low
 
   * comments: Fix commenting, broken by security fix.