Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(theming): Harden admin theming settings #50293

Open
wants to merge 3 commits into
base: master
Choose a base branch
from

Conversation

susnux
Copy link
Contributor

@susnux susnux commented Jan 21, 2025

Summary

Ensure there is no " within the link to prevent XSS.
This is not a security issue as per our threat model as this can only be set by admin and admin can do everything.
But its hardens it (e.g. accidentally using an URL containing a double quote).

Checklist

@susnux susnux added this to the Nextcloud 31 milestone Jan 21, 2025
@susnux susnux requested review from artonge, nfebe and Pytal January 21, 2025 15:06
@susnux
Copy link
Contributor Author

susnux commented Jan 21, 2025

/backport to stable30

@susnux
Copy link
Contributor Author

susnux commented Jan 21, 2025

/backport to stable29

@Altahrim Altahrim mentioned this pull request Jan 21, 2025
@susnux susnux force-pushed the fix/harden-admin-settings branch from 2442f6b to 44b8d85 Compare January 21, 2025 15:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants