Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.89) (envelope-from ) id 1hqa5Y-0006ib-Pe for pgadmin-hackers@arkaria.postgresql.org; Thu, 25 Jul 2019 09:31:04 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.89) (envelope-from ) id 1hqa4d-0008ML-Ve for pgadmin-hackers@arkaria.postgresql.org; Thu, 25 Jul 2019 09:30:07 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.89) (envelope-from ) id 1hqZyK-0008GX-9U for pgadmin-hackers@lists.postgresql.org; Thu, 25 Jul 2019 09:23:36 +0000 Received: from mahout.postgresql.org ([2001:4800:3e1:1::227]) by makus.postgresql.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.92) (envelope-from ) id 1hqZyA-0001WB-L6 for pgadmin-hackers@lists.postgresql.org; Thu, 25 Jul 2019 09:23:34 +0000 Received: from gothos.postgresql.org ([2620:122:b000:7::243]) by mahout.postgresql.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.89) (envelope-from ) id 1hqZy6-0003WH-QU for pgadmin-hackers@lists.postgresql.org; Thu, 25 Jul 2019 09:23:22 +0000 Received: from localhost ([127.0.0.1] helo=gothos.postgresql.org) by gothos.postgresql.org with esmtp (Exim 4.89) (envelope-from ) id 1hqZy4-0005fW-5S for pgadmin-hackers@lists.postgresql.org; Thu, 25 Jul 2019 09:23:20 +0000 Content-Type: multipart/mixed; boundary="===============7933662590522599135==" MIME-Version: 1.0 From: Dave Page To: pgadmin-hackers@lists.postgresql.org Subject: pgAdmin 4 commit: Fix an XSS issue when username contains XSS vulnerabl Message-Id: Date: Thu, 25 Jul 2019 09:23:20 +0000 List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Precedence: bulk --===============7933662590522599135== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Rml4IGFuIFhTUyBpc3N1ZSB3aGVuIHVzZXJuYW1lIGNvbnRhaW5zIFhTUyB2dWxuZXJhYmxlIHRl eHQuIEZpeGVzICM0Mzg2CgpCcmFuY2gKLS0tLS0tCmVsZWN0cm9uMgoKRGV0YWlscwotLS0tLS0t Cmh0dHBzOi8vZ2l0LnBvc3RncmVzcWwub3JnL2dpdHdlYj9wPXBnYWRtaW40LmdpdDthPWNvbW1p dGRpZmY7aD0xMDY3NDM2OGRiY2QwZTk5MTVhM2RkOWEyNjNiNzAwNGUzNGUwMmU1CkF1dGhvcjog QWRpdHlhIFRvc2huaXdhbCA8YWRpdHlhLnRvc2huaXdhbEBlbnRlcnByaXNlZGIuY29tPgoKTW9k aWZpZWQgRmlsZXMKLS0tLS0tLS0tLS0tLS0KZG9jcy9lbl9VUy9yZWxlYXNlX25vdGVzXzRfOS5y c3QgICAgICAgICAgICAgICAgICAgfCAgMyArKy0Kd2ViL3BnYWRtaW4vdG9vbHMvZGF0YWdyaWQv c3RhdGljL2pzL2RhdGFncmlkLmpzICAgfCAyMyArKysrLS0tLS0tLS0tLS0tLS0tLS0tCi4uLntn ZXRfcGFuZWxfdGl0bGUuanMgPT4gZGF0YWdyaWRfcGFuZWxfdGl0bGUuanN9IHwgMjIgKysrKysr KysrKysrKysrKysrKysrCndlYi9wZ2FkbWluL3Rvb2xzL2RhdGFncmlkL3N0YXRpYy9qcy9zaG93 X2RhdGEuanMgIHwgIDIgKy0KLi4uL3Rvb2xzL2RhdGFncmlkL3N0YXRpYy9qcy9zaG93X3F1ZXJ5 X3Rvb2wuanMgICAgfCAgMiArLQp3ZWIvcGdhZG1pbi90b29scy9zcWxlZGl0b3Ivc3RhdGljL2pz L3NxbGVkaXRvci5qcyB8IDEwICsrKystLS0tLS0KLi4uL2phdmFzY3JpcHQvZGF0YWdyaWQvZ2V0 X3BhbmVsX3RpdGxlX3NwZWMuanMgICAgfCAgMiArLQo3IGZpbGVzIGNoYW5nZWQsIDM1IGluc2Vy dGlvbnMoKyksIDI5IGRlbGV0aW9ucygtKQoK --===============7933662590522599135==--