Uploaded image for project: 'XNAT'
  1. XNAT
  2. XNAT-4243

Trying to add a popup to the invalid password warning breaks the site config page

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Critical
    • Resolution: Won't Do
    • Affects Version/s: None
    • Fix Version/s: 1.7
    • Component/s: Admin UI
    • Labels:
    • Environment:

      xnat-dev05

    • Sprint:
      Prebeta push
    • Rank:
      0|ii0un3:
    • Sprint:
      Prebeta push

      Description

      For the invalid password message under Security, I entered instead:

      <script>alert('Your password was wrong');</script>
      

      When I saved and reloaded the site config, it looked like what you see in the screenshot.

        Activity

        Hide
        mfmckay@wustl.edu Mike McKay (Inactive) added a comment -

        I don't think we ever intended to allow arbitrary javascript in those messages. If you think we should, can you lower the priority and take it out of the beta sprint? If it's just a matter of validation to let people know that they shouldn't do this, then this is just part of the bug that exists which is that there is no validation on any AdminUI stuff.

        Show
        mfmckay@wustl.edu Mike McKay (Inactive) added a comment - I don't think we ever intended to allow arbitrary javascript in those messages. If you think we should, can you lower the priority and take it out of the beta sprint? If it's just a matter of validation to let people know that they shouldn't do this, then this is just part of the bug that exists which is that there is no validation on any AdminUI stuff.
        Hide
        moore.c@wustl.edu Charlie Moore added a comment -

        (Future) validation is sufficient in my book.

        Show
        moore.c@wustl.edu Charlie Moore added a comment - (Future) validation is sufficient in my book.

          People

          • Assignee:
            moore.c@wustl.edu Charlie Moore
            Reporter:
            moore.c@wustl.edu Charlie Moore
          • Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:

              Agile