Escape HTML from bug summaries and crash signatures

Fixes #3168
This commit is contained in:
Marco Castelluccio 2022-11-11 20:34:05 +01:00
Родитель ca9131bee3
Коммит 8d630cba1b
1 изменённых файлов: 10 добавлений и 7 удалений

Просмотреть файл

@ -6,6 +6,7 @@
import argparse
import collections
import copy
import html
import itertools
import json
import logging
@ -1368,12 +1369,14 @@ def notification(days: int) -> None:
return (
"|[{}](https://bugzilla.mozilla.org/show_bug.cgi?id={})|{}|{}|{}|".format(
escape_markdown(
html.escape(
textwrap.shorten(
"Bug {} - {}".format(
bug["id"], escape_markdown(full_bug["summary"])
),
"Bug {} - {}".format(bug["id"], full_bug["summary"]),
width=98,
placeholder="",
)
)
),
bug["id"],
last_activity,
@ -1404,7 +1407,7 @@ def notification(days: int) -> None:
top_crashes.append(
"|[{}](https://crash-stats.mozilla.org/signature/?product=Firefox&{}) ({}#{} globally{})|{}{}".format(
escape_markdown(signature),
escape_markdown(html.escape(signature)),
urllib.parse.urlencode({"signature": signature}),
"**" if data["tc_rank"] <= 50 else "",
data["tc_rank"],