]> git.evergreen-ils.org Git - Evergreen.git/commit
LP#1930933: fix issue with over-escaping in search results title attributes
authorGalen Charlton <gmc@equinoxOLI.org>
Mon, 14 Jun 2021 15:34:51 +0000 (11:34 -0400)
committerJeff Davis <jdavis@sitka.bclibraries.ca>
Tue, 15 Jun 2021 21:48:15 +0000 (14:48 -0700)
commit18afce58fcb7c20324a8b3c725ccab35aa35aab8
treebee22f80f341b10d1037c71091bb99bec15e12e4
parent5e71d9d94e3873e0b7b06d8073f1ae224c5d98a2
LP#1930933: fix issue with over-escaping in search results title attributes

This patch fixes an issue where a record with a title containing the
word "hidden" can have its title, ironically enough, not show up
on public catalog search results.

To test
-------
[1] Create an OPAC-visible record whose 245 is something like:

    =245 04$aThe hidden one <script>alert('title!')</script>

[2] Search for the record in both the TPAC and Bootstrap skin. Note
    that the title isn't displayed.
[3] Apply the patch and repeat step 2. This time, the full title
    should be displayed.
[4] Verify that the OPAC does not display an alert box.

Signed-off-by: Galen Charlton <gmc@equinoxOLI.org>
Signed-off-by: Jason Stephenson <jason@sigio.com>
Signed-off-by: Jeff Davis <jdavis@sitka.bclibraries.ca>
Conflicts:
Open-ILS/src/templates-bootstrap/opac/parts/result/table.tt2
Open-ILS/src/templates/opac/parts/result/table.tt2