[
https://issues.apache.org/jira/browse/OFBIZ-12249?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17358120#comment-17358120 ]
Xin Wang commented on OFBIZ-12249:
----------------------------------
Hi Jacques,
Seems that following example will be rejected by this new patch:
{quote}blah blah blah ... (see [
http://example.com/a%20link]) ...
{quote}
I think that for free-form text input widgets, it is really hard to guess what kind of text will be submitted. What we can do is output encoding, instead of input sanitization.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)