No need to revert r30078: HTML-formatting the data is enough. Attacks like api.php...
authorRoan Kattouw <catrope@users.mediawiki.org>
Thu, 24 Jan 2008 13:12:03 +0000 (13:12 +0000)
committerRoan Kattouw <catrope@users.mediawiki.org>
Thu, 24 Jan 2008 13:12:03 +0000 (13:12 +0000)
commitd2cb8c025e0191a49fd68524c10b40c78a11ed6c
tree9838e154377ad2c995b4aab12b5b8d9a3872e57f
parent359b7662a4c0c28821503660865cc3dd2b3fc8f8
No need to revert r30078: HTML-formatting the data is enough. Attacks like api.php?action=paraminfo&modules=%3Cscript%3Ealert('Owned');%3C/script%3E&format=txt don't work anymore now.
RELEASE-NOTES
includes/AutoLoader.php
includes/api/ApiFormatDbg.php [new file with mode: 0644]
includes/api/ApiFormatTxt.php [new file with mode: 0644]
includes/api/ApiMain.php