format html shortens links in HTML attributes
Reported by Jonathan Schreiber | May 12th, 2008 @ 03:10 PM | in Phase Deuce
this renders the HTML unusable b/c you've concatenated the source!
ex:
formatted becomes:
<div style="width:176px;text-align:center"><embed src="http://twitter.com/flash/twitter..." flashvars="color1=3381504&type=user&id=14600116" quality="high" width="176" height="176" name="twitter_badge" align="middle" allowScriptAccess="always" wmode="transparent" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/get..." /><br><a style="font-size: 10px; color: #339900; text-decoration: none" href="http://twitter.com/johnbattelle">follow johnbattelle at http://twitter.com</a></div>
Comments and changes to this ticket
-
Jonathan Schreiber May 12th, 2008 @ 04:57 PM
when I want to paste some HTML into a bug for someone else to copy and paste out, it's impossible via Lighthouse, which is a real bummer!
-
Will May 12th, 2008 @ 05:05 PM
- → State changed from new to open
I'm not quite sure I understand the context of your ticket. Do you mean you want to use rendered html in your ticket?
-
Will May 12th, 2008 @ 05:09 PM
- → Milestone changed from to Phase Deuce
- → Assigned user changed from to rick
Ah, my apologies, it was all in the title of the ticket and my brain just did not computer it at first.
Indeed inside the @@@ it shouldn't truncate the urls. I'll move this ticket over to rick then.
Thanks for pointing that out.
-
rick May 12th, 2008 @ 05:09 PM
- → Milestone cleared.
- → Assigned user cleared.
Sorry, those are some of the measures we take to make sure people don't add XSS exploits to tickets. For now, just upload a text or html file attachment as your example. I'll see about tweaking the parser to skip sanitizing the code areas when I change to Markdown.
-
rick May 12th, 2008 @ 05:10 PM
- → Milestone changed from to Phase Deuce
- → Assigned user changed from to rick
-
Jonathan Schreiber May 13th, 2008 @ 04:42 PM
Oh cool, Markdown will be really nice to have, esp. if we can escape out code areas to not be parsed.
For now, yeah, we're uploading as attachments.
--J
Please Login or create a free account to add a new comment.
You can update this ticket by sending an email to from your email client. (help)
Create your profile
Help contribute to this project by taking a few moments to create your personal profile. Create your profile »
Using Lighthouse to track Lighthouse.
