Bugs in new announcement system

From: David Fetter <david(at)fetter(dot)org>
To: PostgreSQL WWW <pgsql-www(at)postgresql(dot)org>
Subject: Bugs in new announcement system
Date: 2020-11-02 00:10:37
Message-ID: 20201102001037.GB23204@fetter.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-www

Hi,

I just spent an hour trying to figure out how to post the PostgreSQL
Weekly News through the new web form after I spent this morning and
into this afternoon writing it. It would be an understatement to
describe that latter process as onerous and unpleasant.

The attempt to disallow HTML by checking for < in a regex is not super
handy, and it's probably not secure either.

https://git.postgresql.org/gitweb/?p=pgweb.git;a=commitdiff;h=b3e9a962e4514962a1fdbf86b8cdbae3103e76e9

I went and found a library Python provides called Bleach
(https://bleach.readthedocs.io/en/latest/) which should do a much
better job.

Please fix this either by making something that highlights the
offending section(s) so people have some idea what to fix, or renders
them harmless automatically, whichever seems easier. I went to the
trouble of tracking this down because I have a lot of readers each
week who expect me to get it there, but I doubt anyone else who ran
into this bothered.

Best,
David.
--
David Fetter <david(at)fetter(dot)org> http://fetter.org/
Phone: +1 415 235 3778

Remember to vote!
Consider donating to Postgres: http://www.postgresql.org/about/donate

Responses

Browse pgsql-www by date

  From Date Subject
Next Message Dave Page 2020-11-02 08:53:21 Re: sudo inconsistencies in download pages
Previous Message Jaime Casanova 2020-11-01 17:31:02 pgsql-es-ayuda 202010 mbox has a mssing thread