24 Nov
2010
24 Nov
'10
2:29 p.m.
+1 On Wed, Nov 24, 2010 at 2:19 PM, Thomas Mortagne <[email protected]>wrote:
Hi devs,
$xwiki.parseMessage is used to parse velocity located in a translation message.
Thing it for me it's very bad (bad design and very bad for performances and most of all for security) to have velocity in translation messages which makes $xwiki.parseMessage useless and some other would say a security hole (see http://jira.xwiki.org/jira/browse/XWIKI-5684).
So I propose to deprecate it in 2.7 to make sure we don't use that anymore.
WDYT ?
-- Thomas Mortagne _______________________________________________ devs mailing list [email protected] http://lists.xwiki.org/mailman/listinfo/devs