Uploaded image for project: 'eZ Publish / Platform'
  1. eZ Publish / Platform
  2. EZP-21417

Double Quotes wrongly converted after security patch when using urlalias_uri

    Details

      Description

      After applying EZPESU-2013-013-KERNEL4.7 , when using ContentObject names with " (double quotes) are being converted to &quot when the site.ini[URLTranslator]\TransformationGroup variable is set to urlalias_iri and that's causing problems.

      The patch provided in Jira #EZP-21049 fixes the display issue, but the actual urls are still being (wrongly) encoded.

        Issue Links

          Activity

          Eduardo Fernandes (Inactive) created issue -
          Eduardo Fernandes (Inactive) made changes -
          Field Original Value New Value
          Description The ContentObject names with *" (double quotes)* are being converted to *&quot* when the site.ini\[URLTranslator]\TransformationGroup variable is set to urlalias_iri and that's causing problems.

          Afaik, it should leave the quotes as they are.

          The testing were made with EZPESU-2013-013-KERNEL4.7 and the following patch provided in [Jira #EZP-21049|https://jira.ez.no/browse/EZP-21049].
          The ContentObject names with *" (double quotes)* are being converted to *&quot* when the *site.ini\[URLTranslator]\TransformationGroup* variable is set to *urlalias_iri* and that's causing problems.

          Afaik, it should leave the quotes as they are.

          The testing were made with *EZPESU-2013-013-KERNEL4.7* and the following patch provided in [Jira #EZP-21049|https://jira.ez.no/browse/EZP-21049].
          Eduardo Fernandes (Inactive) made changes -
          Attachment url_encoding.jpg [ 16344 ]
          Eduardo Fernandes (Inactive) made changes -
          Status Open [ 1 ] Confirmed [ 10037 ]
          Eduardo Fernandes (Inactive) made changes -
          Attachment url_encoding.jpg [ 16344 ]
          Eduardo Fernandes (Inactive) made changes -
          Attachment url_encoding.jpg [ 16350 ]
          Eduardo Fernandes (Inactive) made changes -
          Attachment url_encoding.jpg [ 16350 ]
          Jarosław Heba made changes -
          Status Confirmed [ 10037 ] InputQ [ 10001 ]
          Jarosław Heba made changes -
          Rank Ranked higher
          Jarosław Heba made changes -
          Rank Ranked higher
          Jarosław Heba made changes -
          Rank Ranked higher
          Jarosław Heba made changes -
          Rank Ranked higher
          Filipe Dobreira (Inactive) made changes -
          Status InputQ [ 10001 ] Development [ 3 ]
          Assignee Filipe Dobreira [ filipe.dobreira@ez.no ]
          Joao Inacio (Inactive) made changes -
          Link This issue relates to EZP-20037 [ EZP-20037 ]
          Joao Inacio (Inactive) made changes -
          Link This issue relates to EZP-21049 [ EZP-21049 ]
          Joao Inacio (Inactive) made changes -
          Description The ContentObject names with *" (double quotes)* are being converted to *&quot* when the *site.ini\[URLTranslator]\TransformationGroup* variable is set to *urlalias_iri* and that's causing problems.

          Afaik, it should leave the quotes as they are.

          The testing were made with *EZPESU-2013-013-KERNEL4.7* and the following patch provided in [Jira #EZP-21049|https://jira.ez.no/browse/EZP-21049].
          After applying *EZPESU-2013-013-KERNEL4.7* , when using ContentObject names with *" (double quotes)* are being converted to *&quot* when the *site.ini\[URLTranslator]\TransformationGroup* variable is set to *urlalias_iri* and that's causing problems.

          The patch provided in [Jira #EZP-21049|https://jira.ez.no/browse/EZP-21049] fixes the display issue, but the actual urls are still being (wrongly) encoded.
          Filipe Dobreira (Inactive) made changes -
          Status Development [ 3 ] Development review [ 10006 ]
          Filipe Dobreira (Inactive) made changes -
          Status Development review [ 10006 ] Development Review done [ 10028 ]
          Fix Version/s 4.5 Maintenance [ 12585 ]
          Fix Version/s 4.6 Maintenance [ 12584 ]
          Filipe Dobreira (Inactive) made changes -
          Status Development Review done [ 10028 ] Documentation done [ 10011 ]
          Pedro Resende (Inactive) made changes -
          Status Documentation done [ 10011 ] QA [ 10008 ]
          Assignee Filipe Dobreira [ filipe.dobreira@ez.no ] Pedro Resende [ pedro.resende@ez.no ]
          Pedro Resende (Inactive) logged work - 22/Aug/13 4:23 PM - edited
          • Time Spent:
            2 hours
             

            Analyse and reproduce issue, write test case and verify the issue has been fixed

          Pedro Resende (Inactive) made changes -
          Remaining Estimate 0 minutes [ 0 ]
          Time Spent 2 hours [ 7200 ]
          Worklog Id 38237 [ 38237 ]
          Pedro Resende (Inactive) made changes -
          Worklog Id 38237 [ 38237 ]
          Pedro Resende (Inactive) made changes -
          Assignee Pedro Resende [ pedro.resende@ez.no ]
          Status QA [ 10008 ] Closed [ 6 ]
          Resolution Fixed [ 1 ]
          André Rømcke made changes -
          Workflow eZ Engineering Scrumban Workflow [ 57756 ] EZ* Development Workflow [ 84141 ]
          Alex Schuster made changes -
          Workflow EZ* Development Workflow [ 84141 ] EZEE Development Workflow [ 122778 ]
          Transition Time In Source Status Execution Times Last Executer Last Execution Date
          Open Open Confirmed Confirmed
          3m 28s 1 eduardo.fernandes@ez.no 16/Aug/13 11:48 AM
          Confirmed Confirmed InputQ InputQ
          3d 2h 10m 1 Jarosław Heba 19/Aug/13 1:59 PM
          InputQ InputQ Development Development
          1d 2h 3m 1 Filipe Dobreira (Inactive) 20/Aug/13 4:02 PM
          Development Development Development Review Development Review
          23h 25m 1 Filipe Dobreira (Inactive) 21/Aug/13 3:28 PM
          Development Review Development Review Development Review done Development Review done
          1h 10m 1 Filipe Dobreira (Inactive) 21/Aug/13 4:38 PM
          Development Review done Development Review done Documentation Review done Documentation Review done
          11s 1 Filipe Dobreira (Inactive) 21/Aug/13 4:38 PM
          Documentation Review done Documentation Review done QA QA
          22h 49m 1 pedro.resende@ez.no 22/Aug/13 3:27 PM
          QA QA Closed Closed
          1h 53m 1 pedro.resende@ez.no 22/Aug/13 5:21 PM

            People

            • Assignee:
              Unassigned
              Reporter:
              Eduardo Fernandes (Inactive)
            • Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:

                Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 2 hours
                2h