ExpressionEngine CMS
Open, Free, Amazing

Thread

This is an archived forum and the content is probably no longer relevant, but is provided here for posterity.

The active forums are here.

Issue with publish page and google chrome

February 05, 2012 8:29am

Subscribe [4]
  • #1 / Feb 05, 2012 8:29am

    GDmac - expocom

    350 posts

    Before filing a bug report, i would like to know if you can replicate this.

    - Publish or edit an entry with google chrome browser
    - insert an image tag in any textarea (or source of a wygwam field), with the full url:
    - click submit

      e.g.

    <a href="http://example.com/images/avatars/default_set/big_horns.jpg">http://example.com/images/avatars/default_set/big_horns.jpg</a>

    - on the subsequent preview page it seems some google chrome xss stuff kicks in.

    The top-menu’s don’t work anymore, because chrome refused to load jquery.
    and in the console you can see something along the lines of:
    Refused to execute a JavaScript script. Source code of script found within request.

    This seems to have to do with a page sending and receiving the same script somehow.
    It would be really helpful if there would be a way around it.
    I guess this might need altering the preview entry page.

  • #2 / Feb 06, 2012 12:50pm

    Shane Eckert

    7174 posts

    Hello GDmac - expocom,

    I was not able to replicate this.

    I am using Google Chrome 16.0.912.77 on an iMac.

    Inserting an image tag into a textarea and saving works great.

    Let’s try something first.

    Please navigate in your Control Panel to Admin->Security And Provacy->Security and Sessions and find the Preference “Apply XSS Filtering to uploaded files?” and shane that to “No” then hit submit and try again.

    Retry the steps listed above and tell me if that makes any change.

    I hope this helps!

    Cheers,

  • #3 / Feb 08, 2012 4:35am

    GDmac - expocom

    350 posts

    hmmz. am on 17.0.963.46 beta, will test this further

  • #4 / Feb 09, 2012 6:45pm

    Shane Eckert

    7174 posts

    Hey GDmac - expocom,

    Sounds good. Let us know what you find.

    Cheers,

  • #5 / Feb 13, 2012 6:16am

    GDmac - expocom

    350 posts

    Ok, tested also in non-beta, has the same issue.
    If i put an img tag with quotes in the textarea, then jquery is not loaded
    However, if i leave off the quotes, it gets thru. now getting even more strange.

  • #6 / Feb 13, 2012 2:49pm

    GDmac - expocom

    350 posts

    Ok, can you please verify on a clean install?
    If you put an img tag in a textarea with a full qualified url,
    then Chrome will show the mentioned error…
    e.g.

    // generates error
    <a href="http://example.com/images/avatar/default_set/big_horns.jpg">http://example.com/images/avatar/default_set/big_horns.jpg</a>
    // no quotes, works ok
    <img=http://example.com/images/avatar/default_set/big_horns.jpg  >
  • #7 / Feb 14, 2012 3:24pm

    Shane Eckert

    7174 posts

    Hello GDmac,

    I am still unable to recreate.

    What version of ExpressionEngine are you on? I am using 2.4.

    I used the following code in a textfield and a textarea. Chrome 17.0.963.46

    <a href="http://static.expressionengine.com/201007/general/ee_logo.png">http://static.expressionengine.com/201007/general/ee_logo.png</a>

    There were no errors.

    Let me know what version you are using.

    Cheers,

  • #8 / Feb 15, 2012 7:55am

    GDmac - expocom

    350 posts

    Shane, images from the same domain as were your EE install is.

    Here is a screencast to show the issue.
    (watch full-screen for better resolution)
    http://www.screenr.com/Pqys

  • #9 / Feb 15, 2012 10:14am

    i’ve come across this issue too, seems to be a bug in chrome http://code.google.com/p/chromium/issues/detail?id=79014

  • #10 / Feb 15, 2012 11:45am

    GDmac - expocom

    350 posts

    Ha Ben, i posted to that chrome bug-report, linking to this thread 😊

    The thing is, i can’t replicate it with a simple form and a bit of php.
    Only when i put actual javascript in a textarea and echo that by php,
    then i got some notice (if i recall correct).

    Was hoping there would be a way around. (Other than advising: use Firefox/Safari)

  • #11 / Feb 15, 2012 11:49am

    ah nice one! well i’m seeing it and i believe it is happening because of a matrix field, would have to look closer though to know for sure. it is only happening when clicking on “Save Revision”, so when redirected back to the edit page. clicking on “Submit” doesn’t cause any errors.

  • #12 / Feb 15, 2012 12:09pm

    GDmac - expocom

    350 posts

    The screencast i posted
    ( http://www.screenr.com/Pqys watch full-screen for better resolution)
    Is a plain vanilla 2.4 install with one field group, with one textarea and one channel using that fieldgroup,
    no other settings changed.

  • #13 / Feb 18, 2012 1:44pm

    shane, i foresee this being a serious issue once enough people upgrade to the latest version of chrome. can you please notify the powers that be at ellislab about this?

  • #14 / Feb 18, 2012 5:03pm

    Shane Eckert

    7174 posts

    Hi Ben,

    I will bring this up with the team and update this thread when I have more news.

    Thanks.

  • #15 / Feb 19, 2012 4:38pm

    thanks shane

.(JavaScript must be enabled to view this email address)

ExpressionEngine News!

#eecms, #events, #releases