[buddypress-trac] [BuddyPress] #983: HTML in profile name field broken again

buddypress-trac at lists.automattic.com buddypress-trac at lists.automattic.com
Mon Sep 7 13:40:01 UTC 2009


#983: HTML in profile name field broken again
-----------------------+----------------------------------------------------
Reporter:  Magganpice  |       Owner:     
    Type:  defect      |      Status:  new
Priority:  major       |   Milestone:     
Keywords:              |  
-----------------------+----------------------------------------------------
 This was fixed quite a while ago but is broken again (as in testing on
 testbp.org).

 Im my profile, I can enter HTML into my profile name field (maybe also
 other fields). This breaks the display in activiy streams.

 For instance I can enter "<strike><em>My Name" into that field and the
 community home page is then "broken".

 My suggestion back then was to strip HTML out of the saved data when
 SAVING, but the problem was solved on the output side by not DISPLAYING
 the HTML. This solution seems not to work anymore. I guess it would be
 better to solve this on the SAVING side, not in the OUTPUT.

-- 
Ticket URL: <http://trac.buddypress.org/ticket/983>
BuddyPress <http://buddypress.org/>
BuddyPress


More information about the buddypress-trac mailing list