PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > ReviewPost Pro Support Forums > ReviewPost Bug Reports

ReviewPost Bug Reports Let us know about any post installation problems you are having with ReviewPost.

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old October 7th, 2005, 03:04 PM   #21 (permalink)
WB
Member
Verified Customer
 
Join Date: Jan 2002
Posts: 265
omegatron:

To make sure we had all the changes (versus the one change we manually made yesterday), I uploaded all of the main level *.php files from the build I just downloaded.

Now we are having the reverse problem.

HTML works as expected in reviews and doesn't get executed since html in reviews is set to off.

In the products though, where html is set to yes, our html javascript and iframes don't get executed/shown properly now.

Are the changes now preventing those from being evaluated when HTML is set to on (for products in our case)?

We are seeing our 'alternate' message for browser's that don't support iframes.

If I revert back to the prior files, all appears correctly.

I suspect that the changes to un_htmlspecialchars may be interfering now even when HTML is set to yes.

Last edited by WB; October 7th, 2005 at 03:10 PM.
WB is offline   Reply With Quote
Old October 7th, 2005, 05:33 PM   #22 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 68,070
Okay not a bug my friend. I don't know of any script that would purposely allow javascript tags as this is the number one way to inject bad code but if you want to allow them then make this small change but this is not something I would be putting in reviewpost. Add the part in bold

Code:
Content visible to verified customers only.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is online now   Reply With Quote
Old October 7th, 2005, 07:41 PM   #23 (permalink)
WB
Member
Verified Customer
 
Join Date: Jan 2002
Posts: 265
Thanks.

In our case we are the only ones who add products and we have HTML off for the reviews so that helps to mitigate the risk (I realize about the injection of bad code since I was the one who pointed out the whole issue in the prior 3.x builds before the switches were added).
WB is offline   Reply With Quote
Old October 9th, 2005, 06:09 AM   #24 (permalink)
Member
 
Join Date: Sep 2003
Posts: 110
So I need to re-upload all of the main level *.php files? (except for config.php)
Mark Goldstein is offline   Reply With Quote
Old October 9th, 2005, 07:51 AM   #25 (permalink)
WB
Member
Verified Customer
 
Join Date: Jan 2002
Posts: 265
Mark:

Yes, that's what we did. We uploaded all of the main level php files with the exception of the config files (and also didn't upload install.php and upgrade.php).

We also made the function un_htmlspecialchars edit (in pp-inc) above to allow the script tag (and another to allow the iframe tag since we use that too) in our products (to "<script><iframe><b><table>.....).

I think our setup is similar to yours in that we are the only ones who post products but we want HTML off in the reviews since users can post those.

Hope this helps.

Have a good weekend.

Last edited by WB; October 9th, 2005 at 07:53 AM.
WB is offline   Reply With Quote
Old October 9th, 2005, 09:25 AM   #26 (permalink)
Member
 
Join Date: Sep 2003
Posts: 110
OK, thank WB, that seems to have fixed the HTML problem.
Mark Goldstein is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
HTML in reviews(FIXED) Arnie ReviewPost Bug Reports 4 October 26th, 2005 06:45 PM
Extra Fields html parse problem(FIXED) rcsmith ReviewPost Bug Reports 3 October 25th, 2005 06:26 PM
Upgrade and settings meko72 Photopost Pro Installation & Upgrades 2 February 9th, 2005 03:01 PM
Either an html page build function, or an html-masking plugin... Khashyar ReviewPost Suggestions 0 July 25th, 2004 12:01 AM


All times are GMT -5. The time now is 12:15 PM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0