Skip to content

fix: secure html module removes target attribute from links #2011 - #2012

Merged
NGPixel merged 1 commit into
requarks:masterfrom
PruvoNet:#2011
Jun 7, 2020
Merged

NGPixel merged 1 commit into
requarks:masterfrom
PruvoNet:#2011

Conversation

@regevbr

@regevbr regevbr commented Jun 7, 2020 •

Copy link
Copy Markdown
Contributor

Fix: #2011

Reproduced the bug on master, and verified the fix

@auto-assign
auto-assign Bot requested a review from NGPixel June 7, 2020 23:01
@regevbr

regevbr commented Jun 7, 2020

Copy link
Copy Markdown
Contributor Author

@NGPixel can you please CR this? The shortest PR you have ever seen :-)

@NGPixel
NGPixel merged commit 037822b into requarks:master Jun 7, 2020
jionggyu pushed a commit to jionggyu/wiki-2.5.302-patch that referenced this pull request Jul 9, 2024
dylan-hart added a commit to dylan-hart/wiki that referenced this pull request Aug 30, 2026
…e-overnight-consolidated-2026-08-25

Resolves overlapping overnight-batch conflicts: duplicate test coverage added
independently for WTable/WDialog/WMenu/anchoredPosition (frontend), theme.js/
url-limit.js (blocks), scheduler.test.ts/system.test.ts/pageProblems.test.ts/
rateLimits.test.ts/security.test.ts (backend), the e2e assets upload spec, and
two independently-added quality.yml check steps (i18n:check + locales:check,
both kept). schema.ts conflicts were comment-wording only, no schema drift.

backend/locales/en.json is reconciled as a full key union of both sides (no
value conflicts except trustProxyHint, resolved in favor of the version that
matches the trustProxyAddresses feature already present) -- a naive text-diff
resolution would have silently dropped ~260 live keys (mail.* templates read
by backend/models/mail.ts, editor conflict-resolution UI, etc.) that the
"theirs" branch's snapshot simply predated.

Also fixes two issues surfaced only once both sides landed together:
- backend/models/storage.test.ts had a duplicate `ensureTemporal` import
  (both branches added it independently in non-conflicting diff hunks).
- Two independent overnight batches each generated the same drizzle migration
  (redundant-index cleanup, OpenProject requarks#2012) under different timestamps;
  kept 20260826014905_main, dropped the later byte-identical duplicate
  20260826045647_main.
- backend/models/rateLimits.test.ts's ban-counting assertion didn't match the
  model's actual (and correctly documented) behavior -- the attempt that
  trips a ban is itself counted as a hit. Corrected the assertion rather than
  the model.

Scoped verification: backend typecheck + oxlint clean; frontend + blocks
oxlint clean; DB-backed backend suites (schema.test.ts, pageProblems.test.ts,
rateLimits.test.ts) and the touched non-DB suites all green against a local
postgres; touched frontend/blocks vitest suites green; oxfmt clean on every
touched file.

Co-Authored-By: Claude Sonnet 5 <[email protected]>
rainforwind pushed a commit to rainforwind/wikijs that referenced this pull request Aug 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug: secure html module removes target attribute from links

2 participants