Support for Drupal 7 is ending on 5 January 2025—it’s time to migrate to Drupal 10! Learn about the many benefits of Drupal 10 and find migration tools in our resource center.
If you put something like
<script>alert('test')</script>
in the comment field (other -> comment), the whole Views UI blows up and becomes unusable beyond repair. You cannot save, cancel or configure anything in that view.
Patch will follow in a minute.
Comment | File | Size | Author |
---|---|---|---|
#2 | script-tag-in-comment-field-blows-ui-1397944-2.patch | 912 bytes | bfr |
Comments
Comment #1
bfr CreditAttribution: bfr commentedHere's a patch.
Comment #2
bfr CreditAttribution: bfr commentedAnd the patch ;)
Comment #3
bfr CreditAttribution: bfr commentedComment #4
dawehnerThanks! Committed to both 6x-3.x and 7.x-3.x
Comment #5
bfr CreditAttribution: bfr commentedOk, great.
By the way, it would be nice if you commited with
git am < filename.patch
so the author would actually get the credit, as described here.
Comment #6
dawehnerOH i never did because most patches don't have that.
Comment #7
bfr CreditAttribution: bfr commentedWell, maybe you could start from this patch? :)
Note, that there is an alternative method:
git commit --author="username <[username]@[uid].no-reply.drupal.org>"
, so for example your patch would be commited like this:git commit --author="dereine <dereine@99340.no-reply.drupal.org>"
.You can use that if the patch is not "git aware". You can tell the difference by looking at the patch:
If it has "email-like header"(like my patch above), then it's formatted correctly and you can use
git am
. Otherwiseyou need to use the --author(or, better, teach the patcher to properly format his/her patches).
Proper authoring is very nice way of saying "thanks", since it makes the project show on authors profile(and, of course, is the proper "git" way of doing things).
Comment #8
dawehnerWell the patch is already committed.
Sadly this adds an additional "overhead" to all patches, but yeah it's worth to do that.
Comment #9
bfr CreditAttribution: bfr commentedEasily fixable:
Yes, proper authoring introduces some overhead but it's the right thing to do to encourage contribution.
Comment #10.0
(not verified) CreditAttribution: commentedTypo