Revert r27581, 27598, 27626
authorBrion Vibber <brion@users.mediawiki.org>
Mon, 19 Nov 2007 15:32:06 +0000 (15:32 +0000)
committerBrion Vibber <brion@users.mediawiki.org>
Mon, 19 Nov 2007 15:32:06 +0000 (15:32 +0000)
commitb61adceeb9001a16fe1570579761edaa7db9c8ca
tree490897c1dfeb0c09166c8b5c7f34bde54ee007a7
parentd7908b82e0e852e6610336fe7110d7ccda9c9bb4
Revert r27581, 27598, 27626
format=raw is an HTML injection machine like action=raw but without any safeguards; it's trivial to create JavaScript exploits which hit at least Internet Explorer.
There's no reason to add a whole new danger point here when you've got machine-readable structure already... please do not add this raw formatter back.
RELEASE-NOTES
includes/AutoLoader.php
includes/GlobalFunctions.php
includes/Wiki.php
includes/api/ApiBase.php
includes/api/ApiExpandTemplates.php
includes/api/ApiFormatBase.php
includes/api/ApiHelp.php
includes/api/ApiMain.php
includes/api/ApiQuery.php
includes/api/ApiRender.php