Skip to content

Fix Bad Escape in Issue Board Empty State

What does this MR do?

This MR fixes that HTML is wrongfully escaped in the "Add issues" modal of issue boards. The fix is done by replacing the sprintf-implementation with the newer GlSprintf GitLab UI component. An advantage is that the component no longer needs to use v-html (or v-safe-html).

Closes #241847 (closed) (because neither v-html nor v-safe-html will be used in the component when this is merged).

Steps to test

  1. Go to a project
  2. Create an issue without any labels
  3. In the left project sidebar, click on Issues -> Boards
  4. Click on "Add issues"
  5. Click on the tab "Selected issues"
  6. See that the normal text doesn't contain escaped HTML (specifically no <strong>...</strong>)

Screenshots

Before (also happens on GitLab.com) After
image image

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:

  • [-] Label as security and @ mention @gitlab-com/gl-security/appsec
  • [-] The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • [-] Security reports checked/validated by a reviewer from the AppSec team
Edited by Kev

Merge request reports

Loading