Vote #78545
完了Render all possible inline textile images
0%
説明
In r15433, Redmine introduced a security measure to restrict embedding images to only those with valid schemes from Textile.
Now, if there are multiple images referenced on a page, with only one of them invalid, Redmine currently doesn't create @@ tags for any of them since it would return from the replacement method too soon.
This patch fixes this behavior in that it still allows to embed all valid images and only refuses to embed the invalid ones by skipping the rest of the current @gsub@ iteration instead of the whole method. The patch was extracted from "Planio":https://plan.io/redmine-hosting/
journals
Confirmed the problem. Setting target version to 3.4.0.
*Markup:*
<pre>
!http://www.cs.cmu.edu/~chuck/lennapg/len_std.jpg!
!data:text/html;base64,iVBORw0KGgoAAAANSUhEUgAAAAgAAAAICAMAAADz0U65AAAABlBMVEX2Ojr///8SFd07AAAAEklEQVQI12Nk/A+FDFCakSwRAPZFHA3MVemHAAAAAElFTkSuQmCC!
</pre>
*Expected (with the patch applied):*
!{border: 1px solid #ccc;}26157-expected.png!
*Actual (without the patch):*
!26157-actual.png!
--------------------------------------------------------------------------------
Committed, thanks!
--------------------------------------------------------------------------------