When the user name contains the [&] symbol, the pop-up deletes the user dialog box and the & symbol is translated.

Bug #1807872 reported by pengyuesheng
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Dashboard (Horizon)
In Progress
Low
pengyuesheng

Bug Description

1、Create a user named sdfs&&dasf
2、Select the user and click to delete the user.
3、The & symbol in the Delete This User dialog box is translated.

Revision history for this message
Akihiro Motoki (amotoki) wrote :

Do you mean "escaped" by "translated"?

I see "sdfs&&dasf".

Changed in horizon:
importance: Undecided → Low
tags: added: low-han
tags: added: low-hanging-fruit
removed: low-han
Revision history for this message
Akihiro Motoki (amotoki) wrote :

NOTE: If someone would like to fix it, you need to consider risk of script injection in other delete forms and other templates carefully.

IMHO this issue is super low-hanging-fruit and very low because it is not common to use such character as username.

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to horizon (master)

Fix proposed to branch: master
Review: https://review.openstack.org/636569

Changed in horizon:
assignee: nobody → pengyuesheng (pengyuesheng)
status: New → In Progress
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.