[ic] html encode problem in get_password.html

Mike Heins interchange-users@interchange.redhat.com
Fri Apr 19 03:32:01 2002


Quoting Kevin Walsh (kevin@cursor.biz):
> > 
> > I have a problem at get_password.html.
> > When password contain a character '[' , it becomes [ on the notification
> > mail.
> > 
> > I think HTML encode cause this problem.
> > Any solution?
> > 
> Edit that file and change the [search-region] tag to read:
> 
>     [search-region safe_data=1]
> 

Recommend not doing that. It is not safe data when in a [PREFIX-data ....]
for the user could type arbitrary code as a password .

-- 
Red Hat, Inc., 3005 Nichols Rd., Hamilton, OH  45013
phone +1.513.523.7621      <mheins@redhat.com>

Few blame themselves until they have exhausted all other possibilities.
 -- anonymous