mirror of
https://github.com/inverse-inc/sogo.git
synced 2026-08-30 02:37:16 +00:00
fix(mail): escape mail data placed in attributes of a compiled part
the generic attribute writer used for these two spots does not escape what it writes, so a value taken from the message ends the attribute and starts a new one. both are inside a part that is compiled, which is where an injected handler runs. * the organizer link took inEvent.organizer.email verbatim. a value such as mailto:x@y" onpointerover="... produced a live handler on the anchor, and an entity encoded scheme such as javascript: reached the href, where the browser decodes it. the href is now built as mailto: plus the parsed address and escaped as an attribute value. * the attachment name paragraph of the image and the link viewer took filenameForDisplay verbatim. a quote inside an RFC 2231 encoded filename ended the title attribute. the writer escapes & < > there but not the quote, so the accessor drops the quote instead of escaping it, which keeps a plain filename such as A&B.pdf unchanged in the tooltip. the img title of the image viewer is left alone: attributes of that element are escaped by the framework already.
This commit is contained in:
@@ -418,6 +418,18 @@
|
||||
return YES;
|
||||
}
|
||||
|
||||
- (NSString *) organizerHref
|
||||
{
|
||||
NSString *address;
|
||||
|
||||
address = [[[self inEvent] organizer] rfc822Email];
|
||||
if (![address length])
|
||||
return nil;
|
||||
|
||||
return [[NSString stringWithFormat: @"mailto:%@", address]
|
||||
stringByEscapingHTMLAttributeValue];
|
||||
}
|
||||
|
||||
- (NSString *) organizerDisplayName
|
||||
{
|
||||
iCalPerson *organizer;
|
||||
|
||||
Reference in New Issue
Block a user