add news item for ikiwiki 2.32.3

master
Joey Hess 2008-02-10 18:58:41 -05:00
parent 78c7f4dc71
commit 886adf9f9f
1 changed files with 18 additions and 0 deletions

View File

@ -0,0 +1,18 @@
ikiwiki 2.32.3 released with [[toggle text="these changes"]]
[[toggleable text="""
* [ Josh Triplett ]
* Do not allow the about: URI scheme; some browsers interpret about:
URIs like a limited version of data: URIs. In particular, some
versions of Internet Explorer interpret arbitrary HTML content in
about: URIs.
* Also filter the attributes cite, longdesc, and usemap, which can contain
URIs.
* [ Joey Hess ]
* meta: Check that the urls provided for authorurl, permalink, and openid
are safe and can't contain javascript.
* [ Josh Triplett ]
* Match literal '.' in URI schemas containing '.', rather than matching any
character.
* Do not allow the steam: URI scheme.
* Allow the snews: URI scheme.
* Allow the smb: URI scheme."""]]