[wp-trac] [WordPress Trac] #13051: admin_url() and site_url() shouldn't need esc_url()

WordPress Trac wp-trac at lists.automattic.com
Mon May 3 17:03:12 UTC 2010


#13051: admin_url() and site_url() shouldn't need esc_url()
--------------------------+-------------------------------------------------
 Reporter:  alexkingorg   |       Owner:  ryan                     
     Type:  defect (bug)  |      Status:  new                      
 Priority:  normal        |   Milestone:  3.0                      
Component:  Security      |     Version:  3.0                      
 Severity:  normal        |    Keywords:  needs-testing needs-patch
--------------------------+-------------------------------------------------

Comment(by nacin):

 While discussing this yesterday, one potential avenue we did not end up
 pursuing on first pass was having sanitize_redirect unescape ampersands.
 Maybe we can consider that as well.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/13051#comment:16>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list