arrow-down arrow at-sign bug check checkbox-checked checkbox-unchecked svg-checkmark chevron-right chevrons-right circle-down circle-left circle-right circle-up cloud2 svg-cross2 download download external-link filter github hash home leaf leaf left link-2 log-in log-out mail menu message-square minus plus radio-checked radio-checked2 radio-unchecked search settings spinner8 target twitter up upload-2 user users warning x zap
  • Home
  • Report a bug
  • Contribute
  • All issues
  • Login

URL: https://webcompat.com/issues/29411

Browser / Version: Firefox 68.0
Operating System: Mac OS X 10.14
Tested Another Browser: No

Problem type: Something else
Description: This webcompat form doesn't escape HTML
Steps to Reproduce:
The form doesn't make it clear it expects markdown. I assumed it's plain text, and pasted in an HTML snippet as part of my report. The HTML was lost, so you've got an incomplete report.

The form should change < to &lt; instead of stripping HTML.
Screenshot Description

Browser Configuration
  • mixed active content blocked: false
  • image.mem.shared: true
  • buildID: 20190407093653
  • tracking content blocked: false
  • gfx.webrender.blob-images: true
  • hasTouchScreen: false
  • mixed passive content blocked: false
  • gfx.webrender.enabled: true
  • gfx.webrender.all: false
  • channel: nightly

Console Messages:

[u'[JavaScript Error: "Content Security Policy: The pages settings blocked the loading of a resource at eval (script-src)."]', u'[JavaScript Error: "Content Security Policy: The pages settings blocked the loading of a resource at inline (script-src)." {file: "https://webcompat.com/issues/29411" line: 1}]', u'[JavaScript Warning: "Request to access cookie or storage on https://www.google-analytics.com/analytics.js was blocked because it came from a tracker and content blocking is enabled." {file: "https://webcompat.com/issues/29411" line: 0}]']

From webcompat.com with ❤️

Please login to edit issues.

View issue on Github

Shortcut: Press l on your keyboard to open the label editor. Shortcut: Press g on your keyboard to be taken to the GitHub view of this page.
🔒 Closed: Duplicate
#29412

webcompat.com - This webcompat form doesn't escape HTML

Opened: 2019-04-13
Reporter: webcompat-bot
Comments: 3
  • Home
  • List of issues
  • About
  • Contribute
  • Contact
  • Privacy Policy
  • Terms of Service
  • Code of Conduct