Convergence Emails With Line Separator HTML Entities (
) Cannot Be Loaded When Using OWASP Sanitizer

(Doc ID 2382107.1)

Last updated on APRIL 11, 2018

Applies to:

Oracle Communications Convergence - Version 3.0.1 and later
Information in this document applies to any platform.

Symptoms

Convergence 3.0.1.4.0
Safari and Chrome on MacOS tested, but this is "browser / version / platform" independent.

When the OWASP sanitizer is enabled, trying to read an email containing an encoded unicode Line Separator [HTML entity (hex)] pops up an error dialog stating "An error occurred while displaying the selected message."

OWASP sanitizer enabled:
mail.htmlsanitizer.enable = true

Some messages cannot be read in Convergence when the OWASP sanitizer is enabled. With the OWASP sanitizer disabled (mail.htmlsanitizer.enable = false) the unicode Line Separator remains encoded as an HTML Entity (hex) and the message loads correctly.

 

 

Changes

In Convergence, enabled the OWASP sanitizer:

mail.htmlsanitizer.enable = true

Cause

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms