<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://pkp.sfu.ca/bugzilla/bugzilla.dtd">

<bugzilla version="4.2.5+"
          urlbase="http://pkp.sfu.ca/bugzilla/"
          
          maintainer="pkp-hosted@sfu.ca"
>

    <bug>
          <bug_id>7957</bug_id>
          
          <creation_ts>2012-10-09 11:48:00 -0700</creation_ts>
          <short_desc>login source parameter needs escaping</short_desc>
          <delta_ts>2012-11-28 02:29:55 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>OJS</product>
          <component>User Interface</component>
          <version>2.4.1</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P3</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Jason Nugent">jason.nugent</reporter>
          <assigned_to name="PKP Support">pkp-support</assigned_to>
          <cc>michael.pkp</cc>
    
    <cc>rfm</cc>
          
          

      

      

      

          <long_desc isprivate="0">
            <commentid>31742</commentid>
            <who name="Jason Nugent">jason.nugent</who>
            <bug_when>2012-10-09 11:48:29 -0700</bug_when>
            <thetext>The login page &apos;source&apos; parameter lacks HTML removal.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <commentid>31747</commentid>
            <who name="Jason Nugent">jason.nugent</who>
            <bug_when>2012-10-10 04:00:04 -0700</bug_when>
            <thetext>strip html from source parameter
https://github.com/pkp/omp/commit/f59a2f01516c7308997353f095b7d8b01848913e</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <commentid>31748</commentid>
            <who name="Jason Nugent">jason.nugent</who>
            <bug_when>2012-10-10 04:00:04 -0700</bug_when>
            <thetext>strip html from source parameter
https://github.com/pkp/pkp-lib/commit/a88fa9f045c6319111381305399044a5338a225c</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <commentid>31749</commentid>
            <who name="Jason Nugent">jason.nugent</who>
            <bug_when>2012-10-10 04:05:02 -0700</bug_when>
            <thetext>strip html from source parameter
https://github.com/pkp/omp/commit/da7f64ee71f3be71882b777a553e36e990df5744</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <commentid>31750</commentid>
              <attachid>3871</attachid>
            <who name="Jason Nugent">jason.nugent</who>
            <bug_when>2012-10-10 04:05:11 -0700</bug_when>
            <thetext>Created attachment 3871
Patch against OMP 1.0b</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <commentid>31751</commentid>
              <attachid>3872</attachid>
            <who name="Jason Nugent">jason.nugent</who>
            <bug_when>2012-10-10 04:05:39 -0700</bug_when>
            <thetext>Created attachment 3872
Patch against OJS pkp-lib 2.4.1</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <commentid>31763</commentid>
            <who name="Michael Felczak">michael.pkp</who>
            <bug_when>2012-10-10 15:36:47 -0700</bug_when>
            <thetext>Hi Jason, a couple of suggestions for the patches here:
- It will help users if we label them as applicable to lib-pkp
- Additional patch/recommended patch listing for OJS 2.3.8</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <commentid>31764</commentid>
            <who name="Jason Nugent">jason.nugent</who>
            <bug_when>2012-10-10 16:05:02 -0700</bug_when>
            <thetext>strip html from source parameter
https://github.com/pkp/pkp-lib/commit/f203912651eff2f08c22243209dd30c73c97a002</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <commentid>31765</commentid>
              <attachid>3873</attachid>
            <who name="Jason Nugent">jason.nugent</who>
            <bug_when>2012-10-10 16:06:08 -0700</bug_when>
            <thetext>Created attachment 3873
Patch against OJS pkp-lib 2.3.8</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <commentid>31766</commentid>
            <who name="Jason Nugent">jason.nugent</who>
            <bug_when>2012-10-10 16:06:51 -0700</bug_when>
            <thetext>Thanks, Michael.  I&apos;ve also started a new recommended patches page for OJS 2.3.8 with this patch.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <commentid>31767</commentid>
            <who name="Michael Felczak">michael.pkp</who>
            <bug_when>2012-10-10 16:26:29 -0700</bug_when>
            <thetext>We&apos;ll likely also need fixes for ocs-stable and ohs-stable ...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <commentid>31768</commentid>
              <attachid>3874</attachid>
            <who name="Jason Nugent">jason.nugent</who>
            <bug_when>2012-10-11 03:54:08 -0700</bug_when>
            <thetext>Created attachment 3874
Patch against OCS pkp-lib 2.3.5</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <commentid>31769</commentid>
              <attachid>3875</attachid>
            <who name="Jason Nugent">jason.nugent</who>
            <bug_when>2012-10-11 03:54:34 -0700</bug_when>
            <thetext>Created attachment 3875
Patch against OHS pkp-lib 2.3.2</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <commentid>31770</commentid>
            <who name="Jason Nugent">jason.nugent</who>
            <bug_when>2012-10-11 03:55:03 -0700</bug_when>
            <thetext>strip html from source parameter
https://github.com/pkp/pkp-lib/commit/ae68891b3c31f0d0342f2c890d83436eee8cd866</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>3871</attachid>
            <date>2012-10-10 04:05:00 -0700</date>
            <delta_ts>2012-10-10 04:05:11 -0700</delta_ts>
            <desc>Patch against OMP 1.0b</desc>
            <filename>omp.patch</filename>
            <type>text/plain</type>
            <size>397</size>
            <attacher>jason.nugent</attacher>
            
              <data encoding="base64">ZGlmZiAtLWdpdCBhL3RlbXBsYXRlcy91c2VyL2xvZ2luLnRwbCBiL3RlbXBsYXRlcy91c2VyL2xv
Z2luLnRwbAppbmRleCAwODM1MzRiLi45Y2VkYTU2IDEwMDY0NAotLS0gYS90ZW1wbGF0ZXMvdXNl
ci9sb2dpbi50cGwKKysrIGIvdGVtcGxhdGVzL3VzZXIvbG9naW4udHBsCkBAIC01Myw3ICs1Myw3
IEBACiAJPGJyIC8+CiB7L2lmfQogCi08aW5wdXQgdHlwZT0iaGlkZGVuIiBuYW1lPSJzb3VyY2Ui
IHZhbHVlPSJ7JHNvdXJjZXxlc2NhcGV9IiAvPgorPGlucHV0IHR5cGU9ImhpZGRlbiIgbmFtZT0i
c291cmNlIiB2YWx1ZT0ieyRzb3VyY2V8c3RyaXBfdW5zYWZlX2h0bWx8ZXNjYXBlfSIgLz4KIAog
e2lmICEgJGltcGxpY2l0QXV0aH0KIAl7ZmJ2Rm9ybUFyZWEgaWQ9ImxvZ2luRmllbGRzIn0KCg==
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>3872</attachid>
            <date>2012-10-10 04:05:00 -0700</date>
            <delta_ts>2012-10-10 16:05:28 -0700</delta_ts>
            <desc>Patch against OJS pkp-lib 2.4.1</desc>
            <filename>ojs2_4_1.patch</filename>
            <type>text/plain</type>
            <size>404</size>
            <attacher>jason.nugent</attacher>
            
              <data encoding="base64">ZGlmZiAtLWdpdCBhL3RlbXBsYXRlcy91c2VyL2xvZ2luLnRwbCBiL3RlbXBsYXRlcy91c2VyL2xv
Z2luLnRwbAppbmRleCAzODNhYzQ4Li5hOGZkODJlIDEwMDY0NAotLS0gYS90ZW1wbGF0ZXMvdXNl
ci9sb2dpbi50cGwKKysrIGIvdGVtcGxhdGVzL3VzZXIvbG9naW4udHBsCkBAIC0zNyw3ICszNyw3
IEBACiAJPGJyIC8+CiB7L2lmfQogCi08aW5wdXQgdHlwZT0iaGlkZGVuIiBuYW1lPSJzb3VyY2Ui
IHZhbHVlPSJ7JHNvdXJjZXxlc2NhcGV9IiAvPgorPGlucHV0IHR5cGU9ImhpZGRlbiIgbmFtZT0i
c291cmNlIiB2YWx1ZT0ieyRzb3VyY2V8c3RyaXBfdW5zYWZlX2h0bWx8ZXNjYXBlfSIgLz4KIAog
e2lmICEgJGltcGxpY2l0QXV0aH0KIAk8dGFibGUgaWQ9InNpZ25pblRhYmxlIiBjbGFzcz0iZGF0
YSI+Cgo=
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>3873</attachid>
            <date>2012-10-10 16:06:00 -0700</date>
            <delta_ts>2012-10-10 16:06:08 -0700</delta_ts>
            <desc>Patch against OJS pkp-lib 2.3.8</desc>
            <filename>ojs-stable-2_3.patch</filename>
            <type>text/plain</type>
            <size>468</size>
            <attacher>jason.nugent</attacher>
            
              <data encoding="base64">ZGlmZiAtLWdpdCBhL3RlbXBsYXRlcy91c2VyL2xvZ2luLnRwbCBiL3RlbXBsYXRlcy91c2VyL2xv
Z2luLnRwbAppbmRleCBkYzAxZGNkLi45MWUyMWI2IDEwMDY0NAotLS0gYS90ZW1wbGF0ZXMvdXNl
ci9sb2dpbi50cGwKKysrIGIvdGVtcGxhdGVzL3VzZXIvbG9naW4udHBsCkBAIC0zOCw3ICszOCw3
IEBACiAJPGZvcm0gaWQ9InNpZ25pbkZvcm0iIG5hbWU9ImxvZ2luIiBtZXRob2Q9InBvc3QiIGFj
dGlvbj0ieyRsb2dpblVybH0iPgogey9pZn0KIAotPGlucHV0IHR5cGU9ImhpZGRlbiIgbmFtZT0i
c291cmNlIiB2YWx1ZT0ieyRzb3VyY2V8ZXNjYXBlfSIgLz4KKzxpbnB1dCB0eXBlPSJoaWRkZW4i
IG5hbWU9InNvdXJjZSIgdmFsdWU9Inskc291cmNlfHN0cmlwX3Vuc2FmZV9odG1sfGVzY2FwZX0i
IC8+CiAKIHtpZiAhICRpbXBsaWNpdEF1dGh9CiAJPHRhYmxlIGlkPSJzaWduaW5UYWJsZSIgY2xh
c3M9ImRhdGEiPgoK
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>3874</attachid>
            <date>2012-10-11 03:54:00 -0700</date>
            <delta_ts>2012-10-11 03:58:42 -0700</delta_ts>
            <desc>Patch against OCS pkp-lib 2.3.5</desc>
            <filename>ocs-stable-2_3.patch</filename>
            <type>text/plain</type>
            <size>468</size>
            <attacher>jason.nugent</attacher>
            
              <data encoding="base64">ZGlmZiAtLWdpdCBhL3RlbXBsYXRlcy91c2VyL2xvZ2luLnRwbCBiL3RlbXBsYXRlcy91c2VyL2xv
Z2luLnRwbAppbmRleCA0YmU4YTY1Li43YTcxNzgxIDEwMDY0NAotLS0gYS90ZW1wbGF0ZXMvdXNl
ci9sb2dpbi50cGwKKysrIGIvdGVtcGxhdGVzL3VzZXIvbG9naW4udHBsCkBAIC0zOCw3ICszOCw3
IEBACiAJPGZvcm0gaWQ9InNpZ25pbkZvcm0iIG5hbWU9ImxvZ2luIiBtZXRob2Q9InBvc3QiIGFj
dGlvbj0ieyRsb2dpblVybH0iPgogey9pZn0KIAotPGlucHV0IHR5cGU9ImhpZGRlbiIgbmFtZT0i
c291cmNlIiB2YWx1ZT0ieyRzb3VyY2V8ZXNjYXBlfSIgLz4KKzxpbnB1dCB0eXBlPSJoaWRkZW4i
IG5hbWU9InNvdXJjZSIgdmFsdWU9Inskc291cmNlfHN0cmlwX3Vuc2FmZV9odG1sfGVzY2FwZX0i
IC8+CiAKIHtpZiAhICRpbXBsaWNpdEF1dGh9CiAJPHRhYmxlIGlkPSJzaWduaW5UYWJsZSIgY2xh
c3M9ImRhdGEiPgoK
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>3875</attachid>
            <date>2012-10-11 03:54:00 -0700</date>
            <delta_ts>2012-10-11 03:59:00 -0700</delta_ts>
            <desc>Patch against OHS pkp-lib 2.3.2</desc>
            <filename>ohs-stable-2_3.patch</filename>
            <type>text/plain</type>
            <size>487</size>
            <attacher>jason.nugent</attacher>
            
              <data encoding="base64">ZGlmZiAtLWdpdCBhL3RlbXBsYXRlcy91c2VyL2xvZ2luLnRwbCBiL3RlbXBsYXRlcy91c2VyL2xv
Z2luLnRwbAppbmRleCBiY2ZiODdjLi42MDcyMzNjIDEwMDY0NAotLS0gYS90ZW1wbGF0ZXMvdXNl
ci9sb2dpbi50cGwKKysrIGIvdGVtcGxhdGVzL3VzZXIvbG9naW4udHBsCkBAIC0zOCw3ICszOCw3
IEBACiAJPGZvcm0gaWQ9InNpZ25pbkZvcm0iIG5hbWU9ImxvZ2luIiBtZXRob2Q9InBvc3QiIGFj
dGlvbj0ie3VybCBwYWdlPSJsb2dpbiIgb3A9InNpZ25JbiJ9Ij4KIHsvaWZ9CiAKLTxpbnB1dCB0
eXBlPSJoaWRkZW4iIG5hbWU9InNvdXJjZSIgdmFsdWU9Inskc291cmNlfGVzY2FwZX0iIC8+Cis8
aW5wdXQgdHlwZT0iaGlkZGVuIiBuYW1lPSJzb3VyY2UiIHZhbHVlPSJ7JHNvdXJjZXxzdHJpcF91
bnNhZmVfaHRtbHxlc2NhcGV9IiAvPgogCiB7aWYgISAkaW1wbGljaXRBdXRofQogCTx0YWJsZSBp
ZD0ic2lnbmluVGFibGUiIGNsYXNzPSJkYXRhIj4KCg==
</data>

          </attachment>
      

    </bug>

</bugzilla>