Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[JENKINS-39618] HTML in portlet 'Display Name' not rendered in versions more recent than 2.9.7 #210

Open
TobiX opened this issue Nov 9, 2016 · 3 comments

Comments

@TobiX
Copy link
Contributor

TobiX commented Nov 9, 2016

Dashboard View Plugin v2.9.10: Does not render HTML in 'Display Name' section
This was very helpful to customize the portlets. Plugin versions up to v2.9.7 correctly render the HTML.


Originally reported by ioannis, imported from: HTML in portlet 'Display Name' not rendered in versions more recent than 2.9.7
  • assignee: tgr
  • status: Open
  • priority: Minor
  • resolution: Unresolved
  • imported: 2022-10-30
@TobiX
Copy link
Contributor Author

TobiX commented Aug 19, 2018

tgr:

This was probably broken by 0855c2c - Need to evaluate if we can safely disable escaping for this field. Probably not, since that would allow users to mount XSS attacks against other users...

@TobiX
Copy link
Contributor Author

TobiX commented Aug 29, 2018

ioannis:

That is rather unfortunate! It was a really useful feature and I was using it a lot. Any other ideas whether we can enhance the display name tabs? Till then I may have to stick to v2.9.7.

Thanks and best regards

@TobiX
Copy link
Contributor Author

TobiX commented Oct 28, 2018

tgr:

Ioannis Moutsatsos This bug is probably in the rich-text-publisher-plugin, there is nothing I can do in the dashboard-view-plugin. Ah, I see now, it's about the portlet titles. I think the functionality can be partially restored by passing the text through the configured markup sanitizer...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant