Re: [pgadmin-hackers] security bug (with patch-fix) -- need moreHTML-escaping for working with tree-nodes - Mailing list pgadmin-hackers

From Dave Page
Subject Re: [pgadmin-hackers] security bug (with patch-fix) -- need moreHTML-escaping for working with tree-nodes
Date
Msg-id CA+OCxoxHMMzgFCQ8hmMx9AtoYcRpVO2KJqLKJNWMf9=KYEJ7qw@mail.gmail.com
Whole thread Raw
In response to Re: [pgadmin-hackers] security bug (with patch-fix) -- need moreHTML-escaping for working with tree-nodes  (Ashesh Vashi <ashesh.vashi@enterprisedb.com>)
Responses Re: [pgadmin-hackers] security bug (with patch-fix) -- need moreHTML-escaping for working with tree-nodes
List pgadmin-hackers


On Wed, May 10, 2017 at 8:56 AM, Ashesh Vashi <ashesh.vashi@enterprisedb.com> wrote:
Thanks.
Committed!

I agree with the change from a preventative/safety perspective, though I'm struggling to classify it as a security issue, given that collections are always named by the code and not from user input. 

Am I missing something?

--
Dave Page
Blog: http://pgsnake.blogspot.com
Twitter: @pgsnake

EnterpriseDB UK: http://www.enterprisedb.com
The Enterprise PostgreSQL Company

pgadmin-hackers by date:

Previous
From: Ashesh Vashi
Date:
Subject: Re: [pgadmin-hackers] security bug (with patch-fix) -- need moreHTML-escaping for working with tree-nodes
Next
From: Ashesh Vashi
Date:
Subject: Re: [pgadmin-hackers] security bug (with patch-fix) -- need moreHTML-escaping for working with tree-nodes