Ticket #3497 (closed Bug: fixed)

Opened 6 years ago

Last modified 6 years ago

Editor name not protected from bad chars

Reported by: notzippy Owned by: tobiasz.cudnik
Priority: Normal Milestone: CKEditor 3.0
Component: General Version: 3.0 Beta 2
Keywords: Confirmed Review+ Cc:

Description

If editor.name="this.is.my.control" then plugin.js causes a javascript error

In plugin.js the following script is used:

Call the temporary function for the editing boostrap.

'window.parent.CKEDITOR._.contentDomReady' + editor.name + '( window );' +

...

Issue is if editor name contains a "." then script will fail - one way to fix this is :

'window.parent.CKEDITOR._[\'contentDomReady' + editor.name + '\']( window );' +

nz

Attachments

3497.patch (543 bytes) - added by tobiasz.cudnik 6 years ago.

Change History

comment:1 Changed 6 years ago by arczi

  • Keywords Confirmed added; Escape editor name removed

comment:2 Changed 6 years ago by tobiasz.cudnik

  • Status changed from new to assigned
  • Owner set to tobiasz.cudnik

Changed 6 years ago by tobiasz.cudnik

comment:3 Changed 6 years ago by tobiasz.cudnik

  • Keywords Review? added

comment:4 Changed 6 years ago by fredck

  • Keywords Review+ added; Review? removed

comment:5 Changed 6 years ago by tobiasz.cudnik

  • Status changed from assigned to closed
  • Resolution set to fixed

Fixed with [3489].

comment:6 Changed 6 years ago by angeloimm

Hi. I tired to apply the patch to my ckeditor; but still i have the sam problem. I opened the file plugin.js located in ckeditor/plugins/wysiwygarea and i modified it. At beginning it was: window.parent.CKEDITOR._.contentDomReady'+c.name+'( window ); i modified it in this way: window.parent.CKEDITOR._\[\"contentDomReady' +c.name+'\"\]( window ); (i added the \ to avoid more wiki formatting) but i have agian the error. Must i do anything else? Thnks Angelo.

comment:7 Changed 6 years ago by arczi

Yes. It should works. For sure please wait for official release.

comment:8 Changed 6 years ago by angeloimm

Ok. I'll wait for the official release....may i know, if possible, when this release is scheduladed? Thanx Angelo.

Note: See TracTickets for help on using tickets.
© 2003 – 2012 CKSource – Frederico Knabben. All rights reserved. | Terms of use | Privacy policy