[jira] [Commented] (OFBIZ-12147) Allow Unsafe Event Message

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

[jira] [Commented] (OFBIZ-12147) Allow Unsafe Event Message

Nicolas Malin (Jira)

    [ https://issues.apache.org/jira/browse/OFBIZ-12147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17269313#comment-17269313 ]

Michael Brohl commented on OFBIZ-12147:
---------------------------------------

The change does not only introduce the UNSAFE_EVENT_MESSAGE but also changes the growl message behaviour with a timeout.

It would be fair and more clear for watchers to mention this with the issue and also in theĀ  commit message.

I would also prefer to give new features more time for review and opinions from the community, this one was proposed and committed within only one day.

> Allow Unsafe Event Message
> --------------------------
>
>                 Key: OFBIZ-12147
>                 URL: https://issues.apache.org/jira/browse/OFBIZ-12147
>             Project: OFBiz
>          Issue Type: Improvement
>          Components: base
>    Affects Versions: Upcoming Branch
>            Reporter: James Yong
>            Assignee: James Yong
>            Priority: Minor
>             Fix For: Upcoming Branch
>
>         Attachments: OFBIZ-12147
>
>
> Currently, we can display flash message by setting in request attribute "__EVENT_MESSAGE__".
>  Propose to add another request attribute i.e. "__UNSAFE_EVENT_MESSAGE__" for messages that can contain inline javascript.
> One use case is to allow us to display last login timestamp with browser-specific format.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)