The "custom CSS" input escapes HTML metacharacters, most notably '>', when saving.

That makes some CSS selectors impossible to enter, which in turn causes some CSS settings to be impossible to override ("foo bar" is less specific than "foo > bar").

Please fix.


smurfix’s picture

Title:Custom CSS escapes HTML meta» Custom CSS escapes HTML meta characters
Jeff Burnz’s picture

Category:Bug report» Feature request
Issue summary:View changes
Status:Active» Closed (works as designed)

Nope, I will not fix it, this is a security issue.