WordPress.org

Make WordPress Core

Opened 6 years ago

Closed 4 years ago

Last modified 4 years ago

#6602 closed defect (bug) (fixed)

kses Should Prevent Duplicate Attributes

Reported by: schiller Owned by:
Milestone: 2.6.1 Priority: normal
Severity: normal Version: 2.6
Component: General Keywords: has-patch 2nd-opinion
Focuses: Cc:

Description

The following is allowed, which would break a blog using strict XHTML:

<a href='foo' href='foo'>blah</a>

Attachments (1)

bug6602.patch (3.0 KB) - added by schiller 6 years ago.
Updated patch to take first attribute and ignore later duplicate attributes (per Sam Ruby's comment)

Download all attachments as: .zip

Change History (12)

comment:1 schiller6 years ago

  • Cc rubys@… added

schiller6 years ago

Updated patch to take first attribute and ignore later duplicate attributes (per Sam Ruby's comment)

comment:2 schiller6 years ago

  • Keywords has-patch 2nd-opinion added; xhtml kses removed

comment:3 schiller6 years ago

  • Milestone changed from 2.7 to 2.5.1

comment:4 lloydbudd6 years ago

  • Milestone changed from 2.5.2 to 2.6
  • Version set to 2.5.1

comment:5 azaozz6 years ago

  • Milestone changed from 2.9 to 2.7

comment:6 azaozz6 years ago

  • Resolution set to fixed
  • Status changed from new to closed

(In [8384]) Take first attribute and ignore later duplicate attributes. Fixes #6602 for trunk. Props schiller.

comment:7 azaozz6 years ago

  • Milestone changed from 2.7 to 2.6.1
  • Resolution fixed deleted
  • Status changed from closed to reopened

Re-open for 2.6.1

comment:8 azaozz6 years ago

  • Resolution set to fixed
  • Status changed from reopened to closed

(In [8385]) Take first attribute and ignore later duplicate attributes. Fixes #6602 for 2.6.1. Props schiller.

comment:9 codedread4 years ago

  • Resolution fixed deleted
  • Status changed from closed to reopened
  • Version changed from 2.5.1 to 2.9.1

Bug appears to still be valid in WP 2.9.1, despite my patch being in kses.php

comment:10 nacin4 years ago

  • Resolution set to fixed
  • Status changed from reopened to closed
  • Version changed from 2.9.1 to 2.6

Re-closing (see #6642:comment:15)

comment:11 rubys4 years ago

  • Cc rubys@… removed
Note: See TracTickets for help on using tickets.