[geeklog-devtalk] RE: [ geeklog-Patches-354 ] HTML Escaping fixes for preview/edit of story.

Michael Jervis mike at fuckingbrit.com
Wed Feb 23 02:42:21 EST 2005


Someone might want to have a look at this patch again... And the other
things, someones posted some random stuff to it.


> -----Original Message-----

> From: noreply at project.geeklog.net

> [mailto:noreply at project.geeklog.net]

> Sent: 22 February 2005 21:04

> To: noreply at project.geeklog.net

> Subject: [ geeklog-Patches-354 ] HTML Escaping fixes for

> preview/edit of story.

>

> Patches item #354, was opened at 2004-12-21 15:11 You can

> respond by visiting:

> http://project.geeklog.net/tracker/?func=detail&atid=107&aid=3

> 54&group_id=6

>

> Category: None

> Group: None

> Status: Open

> Resolution: None

> Priority: 5

> Submitted By: Michael Jervis (themike)

> Assigned to: Nobody (None)

> Summary: HTML Escaping fixes for preview/edit of story.

>

> Initial Comment:

> Provides a fix for:

>

> http://project.geeklog.net/tracker/index.php?func=detail&aid=2

> 5&group_id=6&atid=105

>

> and:

>

> http://project.geeklog.net/tracker/index.php?func=detail&aid=6

> 4&group_id=6&atid=105

>

>

>

> Fixes are applied to:

>

> /public_html/admin/story.php

>

>

>

> Provided:

>

> story.new.php - patch to latest CVS story.php

>

> story.diff - DIFF of story.new.php to latest CVS story.php

>

>

>

> ALSO:

>

> The kses class needs to remove the stripslashes, as geeklog

> stripsslashes already in a billion places:

>

> function Parse($string = "")

>

> {

>

> if (get_magic_quotes_gpc())

>

> {

>

> //$string = stripslashes($string);

>

> }

>

> $string = $this->_no_null($string);

>

> $string = $this->_js_entities($string);

>

> $string = $this->_normalize_entities($string);

>

> $string = $this->_hook($string);

>

> return $this->_split($string);

>

> }

>

>

>

> No file patch provided for the one line comment ;-)

>

> ----------------------------------------------------------------------

>

> Comment By: Nobody (None)

> Date: 2005-02-22 15:04

>

> Message:

> Logged In: NO

>

> ?My pioneer instincts tell me that this plague is prior to

> the one that happened in London? Oliver said. We think that

> Oliver is quite authentic why you might ask? He is one of the

> few that survived the terrible wrath of the plague! Oliver

> was old and he wasn?t able to do the things we were able to

> do! But he was like a god of knowledge; he knew what was

> right and what was wrong because he was very intelligent. He

> was almost 120 years old! 3 more months and he will be 120

> years old! 2 months went by and then a horrid moment came by

> while we were listening to his stories he cried a little,

> when we asked what was wrong he said that it?s all right. The

> next morning came, his birthday, we all clapped and sang and

> danced, we all stopped waiting for Oliver to come out, time

> went by??.. I went searching through his house wishing

> that no one had hurt him. My mind was rushing while I

> searched the house, then I thought the bedroom, maybe he

> accidentally slept in I hoped. I went into

> the bedroom, he was sleeping, or so it seemed. I went to

> awaken him but he wouldn?t, I shook him shook but he did not

> wake up! I cried out loud, ?why now? ?why on this happy day

> have you taken him from us god why? take him tomorrow but not

> on this day please, please let him have one more day!? Oliver

> coughed and said ? thank you my boy, for god has granted you

> you?re wish and I shall live for one more day? when we came

> out all of us rejoiced. Oliver was one great man and he

> lived for one more joyful day. And on that day we played

> games and had fun! Oliver gathered all of us to listen to his

> last story, and here is how the story went, one night, far far away.

>

> There I was standing in front of this giant castle. I was in

> something, wait, I remember now! I was trapped inside a game

> created by a wizard, and the only way out was to beat the

> game. I faced ferocious dragons, huge trolls and powerful

> imps. I had to figure out riddles, puzzles and mazes! Then, I

> finally had to face the all powerful wizard! My power matched

> his, he seemed puzzled! That was my chance I realized, I took

> my sword and stabbed him. He looked pale, he started coughing

> up blood and I wanted to end his misery so I pulled the sword

> out and he passed away. Oliver finished his story and he

> died, we all heard a loud scream almost like dinosaur. A

> dragon appeared and I was the only person fit to fight in my

> town! The dragon surprised us by talking; the dragon said his

> name was reaver. Reaver did not want to hurt us he just

> wanted to be friends, but I gathered all of my friends and

> said ?Oliver said that sometime a dragon might pretend to be

> our friend and when we trust him enough he?ll kill us one by

> one without us knowing?. I designed a plan to kill the dragon

> before he killed us, peter would be the first to try. The

> next day peter grabbed his axe and a staff, he told us it was

> magic so that was the reason he grabbed it. He snuck up

> behind reaver and stabbed him and to our surprise he cast a

> spell on reaver, so now reaver cant breathe fire! Next thing

> you know all of my friends rush over to the dragon and start

> pounding reaver (because they don?t have weapons remember?)

> until he dies. But I couldn?t stand to see another living

> thing die so I shouted ?STOP! I don?t want to see him die, we

> must let him go? I told him to leave our town or else we

> really would have to kill him and I wouldn?t want that to

> happen. Reaver left but as a token for letting him go free he

> said that there is treasure in the mountains and also said if

> we meet again in the mountains he would gladly help us on our

> journey. We bid him good bye and we watched him careful ly

> go towards the mountains. I said well we could go up to the

> mountains and accommodate another story to tell to or young

> ones, anyone with me? Of course my friends went with me, but

> this young lad insisted on coming along. I felt something

> extraordinary about this young man so I said if you want you

> can come along. And so I?ll tell you how this journey went!

> Peter and I were up ahead; we look behind us and saw most of

> our friends out of breath but the young lad who?s name was

> Paul, Paul I haven?t told you yet but he (we found out) was

> the one that wore a mask at every sports competition and

> that?s why he isn?t breathless. Paul ran up to us and said

> that my friends were going back to rest and get nourished,

> also come back with water and more food. I nodded and said

> ?you better go back too Paul just in case because you might

> need nourishment? ?I am not going back I want to see the

> whole thing, because something might happen when I?m gone

> so?. I?m not leaving!? Paul said. ?th en lets get going

> then, Peter, Paul we must not let anything get in our way!? I

> said. We traveled on and Paul was a great help to us here is

> one of the things that Paul did for us, I was lying down to

> get some rest and Paul ran into the woods and seconds later

> he cam out with a gigantic lion with its neck severed. He

> said he thought he saw something in the woods that was following us.

>

>

>

> ----------------------------------------------------------------------

>

> Comment By: Michael Jervis (themike)

> Date: 2004-12-22 13:42

>

> Message:

> Logged In: YES

> user_id=257

>

> Missing htmlspecialchars for HTML stories into the editor in

> previous file, here's the updated patch.

>

> ----------------------------------------------------------------------

>

> You can respond by visiting:

> http://project.geeklog.net/tracker/?func=detail&atid=107&aid=3

> 54&group_id=6

>

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3030 bytes
Desc: not available
Url : <http://eight.pairlist.net/pipermail/geeklog-devtalk/attachments/20050223/e2b36a56/attachment.bin>


More information about the geeklog-devtalk mailing list