I've implemented a new converter for the string context that uses check_plain() to remove potentially dangerous HTML from the string.

CommentFileSizeAuthor
2009-09-02-string-context-html_safe.patch1.29 KBmikl

Comments

merlinofchaos’s picture

Status: Needs review » Fixed

WOrks for me. Committed!

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.