##// END OF EJS Templates
security: fix XSS in repo strip view.
ergo -
r2155:a81b6ebb default
parent child Browse files
Show More
@@ -70,8 +70,8 b' class StripView(RepoAppView):'
70 data[i] = {'rev': None, 'commit': h.escape(rp[chset])}
70 data[i] = {'rev': None, 'commit': h.escape(rp[chset])}
71 else:
71 else:
72 data[i] = {'rev': data[i].raw_id, 'branch': data[i].branch,
72 data[i] = {'rev': data[i].raw_id, 'branch': data[i].branch,
73 'author': data[i].author,
73 'author': h.escape(data[i].author),
74 'comment': data[i].message}
74 'comment': h.escape(data[i].message)}
75 else:
75 else:
76 break
76 break
77 return data
77 return data
General Comments 0
You need to be logged in to leave comments. Login now