Skip to content

Fixing quote functionality, adding quote icon to the comment editor#1504

Open
JimKnoxx wants to merge 1 commit intogetfider:mainfrom
JimKnoxx:1500-quoting
Open

Fixing quote functionality, adding quote icon to the comment editor#1504
JimKnoxx wants to merge 1 commit intogetfider:mainfrom
JimKnoxx:1500-quoting

Conversation

@JimKnoxx
Copy link
Copy Markdown
Contributor

@JimKnoxx JimKnoxx commented Apr 16, 2026

Issue: #1500

In #1495 a XSS vulnerability was fixed by sanitizing the editor output. This broke quoting.

I propose to only quote the < character in this case, so quoting still remain in tact. I am unsure though, if this would open possible xss vulnerabilities again.

Also adding a dedicated quoting button to the editor for better UX.

Co-Authored-By: Claude <noreply@anthropic.com>
@mattwoberts
Copy link
Copy Markdown
Contributor

Thanks @JimKnoxx - #1495 had been pulled into main and I was going to test all this stuff with it before releasing to cloud and updating the verion - you beat me to it! I did suspect this might happen...

I'll take a look at the issue, and your proposed fix too

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants