##// END OF EJS Templates
security: fixed XSS inside the tooltip for author string.
marcink -
r1779:7a1d008d default
parent child Browse files
Show More
@@ -894,7 +894,8 b' def author_string(email):'
894 user = User.get_by_email(email, case_insensitive=True, cache=True)
894 user = User.get_by_email(email, case_insensitive=True, cache=True)
895 if user:
895 if user:
896 if user.firstname or user.lastname:
896 if user.firstname or user.lastname:
897 return '%s %s <%s>' % (user.firstname, user.lastname, email)
897 return '%s %s <%s>' % (
898 escape(user.firstname), escape(user.lastname), email)
898 else:
899 else:
899 return email
900 return email
900 else:
901 else:
General Comments 0
You need to be logged in to leave comments. Login now