Closed jendib closed 8 years ago
https://github.com/ACRA/acra-storage/blob/master/lists/rss.js <-- looks like nothing is escaped.
If @KevinGaudin doesn't get to it first, I'll try to get my dev env setup again tonight, It looks like an easy one to try and get back into it.
Great thank you!
This is great, thank you very much for both commits :+1:
Hmm, it seems it's not quite over, the title needs to be escaped too:
<title>
android.view.InflateException: Binary XML file line #1: Error inflating class <unknown> : at
com.sismics.reader.ui.adapter.SubscriptionAdapter.getView(SubscriptionAdapter.java:86)
</title>
boo. Would you be up for throwing up a test record that doesn't work so I can test easier?
Do you have an email address? There is some sensitive data in it :)
yea sure, halkeye@gmail.com works fine
should this be closed before its merged?
I have this kind of data in the RSS feed:
As you can see, there is a fake
<unknown>
tag in the error generated by Android, which causes the feed to be invalid. The content of<description>
needs to be escaped.