- Try saving changes to a template with a task named "New <client> database from backup."
- There's no saved message nor error; it simply doesn't save.
I don't know if it's limited to only angle brackets; I didn't test other characters.
I don't know if it's limited to only angle brackets; I didn't test other characters.
Hi John,
When trying to save a template with <>, the server returns the error "A potentially dangerous Request.Form value was detected from the client".
For the next release, we will catch the error and show a message when it happens.
Regards,
David.
Hi David,
Why only return the error message rather than fix it? I'm able to create work items named "New <client> database from backup." so why not allow templates to be defined with those names?
2 Comments