liquid_feedback_frontend
diff app/main/member/history.lua @ 46:aaba4d28dd53
Added missing HTML encoding for page titles (security fix!)
| author | bsw | 
|---|---|
| date | Mon Mar 15 03:04:19 2010 +0100 (2010-03-15) | 
| parents | 0ee1e0c42d4c | 
| children | 07177cd8c256 | 
   line diff
1.1 --- a/app/main/member/history.lua Mon Mar 08 22:59:41 2010 +0100 1.2 +++ b/app/main/member/history.lua Mon Mar 15 03:04:19 2010 +0100 1.3 @@ -1,6 +1,6 @@ 1.4 local member = Member:by_id(param.get_id()) 1.5 1.6 -slot.put_into("title", _("Member name history for '#{name}'", { name = member.name })) 1.7 +slot.put_into("title", encode.html(_("Member name history for '#{name}'", { name = member.name }))) 1.8 1.9 slot.select("actions", function() 1.10 ui.link{