View Issue Details

IDProjectCategoryView StatusLast Update
0022543mantisbtuipublic2017-03-20 04:33
ReportervboctorAssigned Tovboctor 
PrioritynormalSeverityfeatureReproducibilityalways
Status assignedResolutionopen 
Product Version2.2.2 
Target VersionFixed in Version 
Summary0022543: Open images in the browser rather than download them
Description

When clicking on an image, open it in the browser rather than downloading it to the user's machine.

TagsNo tags attached.

Relationships

duplicate of 0012313 acknowledged Can't open image attachments in browser windows 
related to 0011952 closeddhx Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks 

Activities

vboctor

vboctor

2017-03-19 22:19

manager   ~0056120

PR: https://github.com/mantisbt/mantisbt/pull/1057

atrol

atrol

2017-03-20 04:33

developer   ~0056122

@vboctor, if I understand right, the functionality has been deactivated in 1.2.2 0011952 due to security reasons, confirmed again at 0012313:0026545.

Issue History

Date Modified Username Field Change
2017-03-19 22:10 vboctor New Issue
2017-03-19 22:10 vboctor Status new => assigned
2017-03-19 22:10 vboctor Assigned To => vboctor
2017-03-19 22:19 vboctor Note Added: 0056120
2017-03-20 04:29 atrol Relationship added duplicate of 0012313
2017-03-20 04:30 atrol Relationship added related to 0011952
2017-03-20 04:33 atrol Note Added: 0056122