[#110736] Can't sign in to bugs.ruby-lang.org — Daniel Berger <djberg96@...>
Hi,
4 messages
2022/11/13
[ruby-core:110566] [Ruby master Feature#19090] Do not duplicate an unescaped string in CGI.escapeHTML
From:
"Dan0042 (Daniel DeLorme)" <noreply@...>
Date:
2022-11-01 12:55:39 UTC
List:
ruby-core #110566
SXNzdWUgIzE5MDkwIGhhcyBiZWVuIHVwZGF0ZWQgYnkgRGFuMDA0MiAoRGFuaWVsIERlTG9ybWUp LgoKCkkgYWdyZWUgdGhlIGR1cCBpcyB1bm5lY2Vzc2FyeSBzaW5jZSA5OS45OSUgb2YgdGhlIHRp bWUgeW91J3JlIGp1c3QgZG9pbmcgYGJ1ZiA8PCBDR0kuZXNjYXBlSFRNTChzdHIpYC4gTm90IHN1 cmUgdGhlIHBlcmZvcm1hbmNlIGdhaW4gd291bGQgYmUgbWVhc3VyYWJsZS4gQSBuZXcgbWV0aG9k IGxpa2UgYENHSS5lc2NhcGVIVE1MIWAgd291bGQgbWFrZSBzZW5zZSB0byBtZSwgYXMgaXQgaW5k aWNhdGVzIHRoZSBkYW5nZXIgb2YgbXV0YXRpbmcgdGhlIHJldHVybiB2YWx1ZS4gCgpJIGRpZCBh IHNlYXJjaCBmb3IgYENHSS5lc2NhcGVIVE1MYCBpbiBnZW1zOiBodHRwczovL3Bhc3RlYmluLmNv bS83SFlVVEFTWgpUaGVyZSdzIGEgbG90IG9mIHNhZmUgdXNhZ2Ugd2hlcmUgdGhlIHJlc3VsdCBp cyBkaXJlY3RseSB1c2VkIGluIGludGVycG9sYXRpb24gb3IgY29uY2F0ZW5hdGlvbi4KVGhlcmUn cyBhbHNvIHNvbWUgInBvdGVudGlhbGx5IHVuc2FmZSIgdXNhZ2UgbGlrZQpgYGBydWJ5CiAgICAg IGRlZiBlc2NhcGVfaHRtbChzdHJpbmcpCiAgICAgICAgQ0dJLmVzY2FwZUhUTUwoc3RyaW5nKQog ICAgICBlbmQKYGBgCndoaWNoIGRlcGVuZHMgb24gaG93IHRoZSBgZXNjYXBlX2h0bWxgIG1ldGhv ZCBpcyBjYWxsZWQsIGJ1dCBpbiBnZW5lcmFsIHRoZSBvbmx5IHZhbGlkIHVzZSBjYXNlIGZvciB0 aGVzZSBtZXRob2RzIGlzIHdoZW4gYXBwZW5kaW5nIHRvIGEgYnVmZmVyLiBTbyBJJ2Qgc2F5IGl0 J3MgYSBsb3ctcmlzayBjaGFuZ2UuCgotLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t LS0tLS0tCkZlYXR1cmUgIzE5MDkwOiBEbyBub3QgZHVwbGljYXRlIGFuIHVuZXNjYXBlZCBzdHJp bmcgaW4gQ0dJLmVzY2FwZUhUTUwKaHR0cHM6Ly9idWdzLnJ1YnktbGFuZy5vcmcvaXNzdWVzLzE5 MDkwI2NoYW5nZS05OTg5NwoKKiBBdXRob3I6IGswa3VidW4gKFRha2FzaGkgS29rdWJ1bikKKiBT dGF0dXM6IE9wZW4KKiBQcmlvcml0eTogTm9ybWFsCi0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t LS0tLS0tLS0tLS0tLS0KIyMgUHJvcG9zYWwKU3RvcCBndWFyYW50ZWVpbmcgdGhhdCBgR0dJLmVz Y2FwZUhUTUxgIHJldHVybnMgYSBuZXcgc3RyaW5nIGV2ZW4gaWYgdGhlcmUncyBub3RoaW5nIHRv IGJlIGVzY2FwZWQuCgpNb3JlIHNwZWNpZmljYWxseSwgc3RvcCBjYWxsaW5nIHRoaXMgYHJiX3N0 cl9kdXBgIGh0dHBzOi8vZ2l0aHViLmNvbS9ydWJ5L2NnaS9ibG9iL3YwLjMuMy9leHQvY2dpL2Vz Y2FwZS9lc2NhcGUuYyNMNzIgZm9yIHRoZSBjYXNlIHRoYXQgbm90aGluZyBuZWVkcyB0byBiZSBl c2NhcGVkLgoKIyMgQmFja2dyb3VuZApNeSBvcmlnaW5hbCBpbXBsZW1lbnRhdGlvbiBodHRwczov L2dpdGh1Yi5jb20vcnVieS9ydWJ5L3B1bGwvMTE2NCB3YXMgbm90IGNhbGxpbmcgaXQuIFRoZSBy ZWFzb24gd2h5IGByYl9zdHJfZHVwYCB3YXMgYWRkZWQgd2FzIHRoYXQgW0J1ZyAjMTE4NThdIGNs YWltZWQgcmV0dXJuaW5nIHRoZSBhcmd1bWVudCBvYmplY3QgZm9yIG5vbi1lc2NhcGVkIGNhc2Vz IGlzIGEgYmFja3dhcmQgaW5jb21wYXRpYmlsaXR5IGJlY2F1c2UgdGhlIG9yaWdpbmFsIGBnc3Vi YC1iYXNlZCBpbXBsZW1lbnRhdGlvbiBhbHdheXMgcmV0dXJucyBhIG5ldyBvYmplY3QuIEFzIGEg cmVzdWx0LCBldmVuIHdoaWxlIG1hbnkgcGVvcGxlIHVzZSBgQ0dJLmVzY2FwZUhUTUxgIGFzIGFu IG9wdGltaXplZCBpbXBsZW1lbnRhdGlvbiBmb3IgZXNjYXBpbmcgSFRNTCB0b2RheSwgaXQgZW5k ZWQgdXAgaGF2aW5nIGEgY29tcHJvbWlzZWQgcGVyZm9ybWFuY2UuCgojIyBNb3RpdmF0aW9uClRo ZSBtb3RpdmF0aW9uIGlzIHRvIGltcHJvdmUgcGVyZm9ybWFuY2UuIEJ5IGp1c3QgZG9pbmcgc28s IGVzY2FwaW5nIGEgcHJlLWFsbG9jYXRlZCBgInN0cmluZyJgIGJlY29tZXMgMS4zNHggZmFzdGVy IG9uIG15IG1hY2hpbmUgaHR0cHM6Ly9naXN0LmdpdGh1Yi5jb20vazBrdWJ1bi9mNjZkNmZlMWU2 YmE4MjFlNDI2MzI1N2U1MDRiYTI4Zi4KClRoZSBtb3N0IG1ham9yIHVzZSBjYXNlIG9mIGBDR1Au ZXNjYXBlSFRNTGAgaXMgdG8gc2FmZWx5IGVtYmVkIGEgdXNlciBpbnB1dC4gV2hlbiB0aGUgcmVz dWx0IGlzIGp1c3QgZW1iZWRkZWQgaW4gYW5vdGhlciBzdHJpbmcsIHRoZSBhbGxvY2F0ZWQgbmV3 IG9iamVjdCB3aWxsIGJlIGp1c3Qgd2FzdGVkLiBJdCdzIHByZXR0eSBjb21tb24gdGhhdCBhbiBl bWJlZGRlZCBzdHJpbmcgZnJhZ21lbnQgZG9lc24ndCBjb250YWluIGFueSBvZiBgJyImPD5gIGNo YXJhY3RlcnMuIFNvIHdlIHNob3VsZCBzdG9wIHdhc3RpbmcgdGhhdCB0byBvcHRpbWl6ZSB0aGF0 IGNhc2UuCgpbQnVnICMxMTg1OF0gd2Fzbid0IHJlYWxseSBhIHVzZSBjYXNlIGJ1dCBqdXN0ICJJ IHRoaW5rIHRoaXMgaXMgYmFja3dhcmQgaW5jb21wYXRpYmlsaXR5IiBiYXNlZCBvbiBmcm96ZW4g SGVsbG8gV29ybGQuIFVubGlrZSB1c2VyIGlucHV0LCB5b3UgdXN1YWxseSBkb24ndCBuZWVkIHRv IGVzY2FwZSB5b3VyIG93biBzdHJpbmcgbGl0ZXJhbC4gSXQgZmVlbHMgbGlrZSB0aGUgdGlja2V0 IGFkZHJlc3NlZCBhIHByb2JsZW0gdGhhdCBkb2Vzbid0IGV4aXN0IGluIGFjdHVhbCBhcHBsaWNh dGlvbnMuIEl0IHNob3VsZCBoYXZlIGNpdGVkIGV4aXN0aW5nIGNvZGUgdGhhdCBjb3VsZCBiZSBi cm9rZW4gYnkgdGhhdCwgYW5kIEkgY2FuJ3QgZmluZCBzdWNoIGNvZGUgd2l0aCBgZ2VtLWNvZGVz ZWFyY2hgIHRvZGF5LgoKVGhlIG9ubHkgcmVhc29uIHRvIG1haW50YWluIHRoZSBjdXJyZW50IGJl aGF2aW9yIHdvdWxkIGJlIHRvIGFsbG93IHVzaW5nIGEgcmV0dXJuIHZhbHVlIG9mIGBDR0kuZXNj YXBlSFRNTGAgYXMgYSBidWZmZXIgZm9yIGNyZWF0aW5nIGFub3RoZXIgbG9uZ2VyIHN0cmluZyBz dGFydGluZyB3aXRoIHRoZSBlc2NhcGVkIHZhbHVlLCBidXQgdXNpbmcgYENHSS5lc2NhcGVIVE1M YCB0byBpbml0aWFsaXplIGEgc3RyaW5nIGJ1ZmZlciBmZWVscyBsaWtlIGFuIGFidXNlLiBSZWx5 aW5nIG9uIHRoZSBiZWhhdmlvciBuZXZlciBtYWtlcyBzZW5zZSBhcyBhbiAib3B0aW1pemF0aW9u IiBlaXRoZXIgYmVjYXVzZSBpdCBtYWtlcyBhbGwgb3RoZXIgY2FzZXMgKHRoZSByZXN1bHQgaXMg bm90IHVzZWQgYXMgYSBzdHJpbmcgYnVmZmVyKSBzdWJvcHRpbWFsLgoKIyMgV2h5IG5vdCBhbiBv cHRpb25hbCBmbGFnIGxpa2UgYENHSS5lc2NhcGVIVE1MKHN0ciwgZHVwOiBmYWxzZSlgPwpUd28g cmVhc29uczoKCiogVGhlIG5vbi1kdXAgYmVoYXZpb3Igc2hvdWxkIGJlIHVzZWQgOTkuOTk5Li45 JSBvZiB0aGUgdGltZS4gV2Ugc2hvdWxkbid0IG1ha2UgY29kZSB1c2luZyBgQ0dJLmVzY2FwZUhU TUxgIGxlc3MgcmVhZGFibGUganVzdCBmb3IgbWFpbnRhaW5pbmcgYSB1c2UgY2FzZSB0aGF0IGRv ZXNuJ3QgZXhpc3QuCiogUGFzc2luZyBrZXl3b3JkIGFyZ3VtZW50cyB0byBhIEMgZXh0ZW5zaW9u IGlzIHVuZm9ydHVuYXRlbHkgc2xvdywgYW5kIGl0IGRlZmVhdHMgdGhlIG9wdGltaXphdGlvbiBw dXJwb3NlLiBJbiBjb3JlIGNsYXNzZXMsIHdlIGNvdWxkIHVzZSBgUHJpbWl0aXZlYCB0byBhZGRy ZXNzIHRoYXQsIGJ1dCB0aGlzIGlzIGEgZGVmYXVsdCBnZW0gYW5kIHdlIGNhbid0IHVzZSB0aGF0 LgogICogV2UgY291bGQgd29ya2Fyb3VuZCB0aGF0IGlmIHdlIGNob29zZSBgQ0dJLmVzY2FwZUhU TUwoc3RyLCBmYWxzZSlgLCBidXQgYWdhaW4gaXQnZCBzcG9pbCB0aGUgcmVhZGFiaWxpdHkgZm9y IG1haW50YWluaW5nIGFuIGludmFsaWQgdXNlIGNhc2UuCgojIyBXaHkgbm90IGEgbmV3IG1ldGhv ZD8KCkl0J3MgYSBnb29kIGlkZWEgYWN0dWFsbHksIGJ1dCB3aXRoIGBlc2NhcGVIVE1MYCwgYGVz Y2FwZV9odG1sYCwgYW5kIGBoYCBhbGlhc2VkIHRvIGl0IGFscmVhZHksIEkgY2FuJ3QgdGhpbmsg b2YgYSBnb29kIG5hbWUgZm9yIGl0LiBBbmQgYWdhaW4sIG5vdCBjYWxsaW5nIGl0IGBlc2NhcGVI VE1MYCBvciBgZXNjYXBlX2h0bWxgIHdvdWxkIHNwb2lsIHRoZSByZWFkYWJpbGl0eSBmb3Igbm8g dmFsaWQgcmVhc29uLgoKCgotLSAKaHR0cHM6Ly9idWdzLnJ1YnktbGFuZy5vcmcvCgpVbnN1YnNj cmliZTogPG1haWx0bzpydWJ5LWNvcmUtcmVxdWVzdEBydWJ5LWxhbmcub3JnP3N1YmplY3Q9dW5z dWJzY3JpYmU+CjxodHRwOi8vbGlzdHMucnVieS1sYW5nLm9yZy9jZ2ktYmluL21haWxtYW4vb3B0 aW9ucy9ydWJ5LWNvcmU+Cg==