liquid_feedback_frontend

diff app/main/member/history.lua @ 46:aaba4d28dd53

Added missing HTML encoding for page titles (security fix!)
author bsw
date Mon Mar 15 03:04:19 2010 +0100 (2010-03-15)
parents 0ee1e0c42d4c
children 07177cd8c256
line diff
     1.1 --- a/app/main/member/history.lua	Mon Mar 08 22:59:41 2010 +0100
     1.2 +++ b/app/main/member/history.lua	Mon Mar 15 03:04:19 2010 +0100
     1.3 @@ -1,6 +1,6 @@
     1.4  local member = Member:by_id(param.get_id())
     1.5  
     1.6 -slot.put_into("title", _("Member name history for '#{name}'", { name = member.name }))
     1.7 +slot.put_into("title", encode.html(_("Member name history for '#{name}'", { name = member.name })))
     1.8  
     1.9  slot.select("actions", function()
    1.10    ui.link{

Impressum / About Us