EE - Improve slash command stripping, escape temporary note contents
What does this MR do?
https://gitlab.com/gitlab-org/gitlab-ce/merge_requests/11341
This MR is an EE port ofFixes two bugs around Instant comments that were introduced in %9.2 with https://gitlab.com/gitlab-org/gitlab-ce/merge_requests/10760
-
Comment contents shown as temporary note is vulnerable to XSS (writing
<script>alert('Boom!');</script>
is not escaped). -
Slash command stripping should also include parameters provided to slash command.
Why was this MR needed?
This MR fixes regression around Instant comments feature as mentioned above.
Screenshots (if relevant)
Does this MR meet the acceptance criteria?
[ ] Changelog entry added, if necessary[ ] Documentation created/updated[ ] API support added- Tests
-
Added for this feature/bug -
All builds are passing
-
-
Conform by the merge request performance guides -
Conform by the style guides -
Branch has no merge conflicts with master
(if it does - rebase it please) -
Squashed related commits together