More of a Nuisance than a Bug
Posted: Fri Feb 13, 2009 10:29 am
As a site administrator, I may wish to enter a link to a manufacturer's website within a product description or a link to a resource or reference in an information description. However, when entering the link in the description field (and I do use "source mode"), after clicking the save button, the quotes in the link get "escaped" to """.
Now, I do understand the security issues involved (SQL injection and the like), but surely this should only be necessary on the front end where unscrupulous visitors to your site may try to compromise (or hack) your system.
Is it really necessary to include this "escaping" of characters within the administration area, where it is reasonable to assume that only the site administrator (or those authorized by the administrator) would be likely to be making these sorts or entries?
Fido-X.
Now, I do understand the security issues involved (SQL injection and the like), but surely this should only be necessary on the front end where unscrupulous visitors to your site may try to compromise (or hack) your system.
Is it really necessary to include this "escaping" of characters within the administration area, where it is reasonable to assume that only the site administrator (or those authorized by the administrator) would be likely to be making these sorts or entries?
Fido-X.