Skip to content

GitLab

  • Menu
Projects Groups Snippets
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • G gitlabhq1
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 21
    • Issues 21
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 12
    • Merge requests 12
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Monitor
    • Monitor
    • Incidents
  • Packages & Registries
    • Packages & Registries
    • Package Registry
    • Infrastructure Registry
  • Analytics
    • Analytics
    • CI/CD
    • Repository
    • Value stream
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • gpt
  • large_projects
  • gitlabhq1
  • Merge requests
  • !8327

Closed
Created Nov 16, 2014 by Administrator@rootOwner
  • Report abuse
Report abuse

Don't render old data project / group names tags [can be updated]

  • Overview 2
  • Commits 1
  • Changes 4

Created by: cirosantilli

which could be added to the database before the current column validation was in place.

Before this PR, sanitize would allow good tags to be rendered and remove bad tags like script.

After this, any tags will be HTML escaped instead of sanitized, so both bad and good tags will appear escaped.

Rationale: people who entered data earlier should not be able to do things that newer users can't. When we forbid something from being done, we should warn users who did it to prepare to migrate.

This continues the discussions at: https://github.com/gitlabhq/gitlabhq/pull/8107#issuecomment-61004035

Assignee
Assign to
Reviewer
Request review from
Time tracking
Source branch: github/fork/cirosantilli/disallow-old-data-magic