Skip to content

Commit ab61063

Browse files
committed
Added escaping of changelist content for the /release/ pages.
- Legacy-Id: 9827
1 parent 1d4dd91 commit ab61063

1 file changed

Lines changed: 2 additions & 1 deletion

File tree

ietf/release/views.py

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@
77
from django.shortcuts import render_to_response
88
from django.conf import settings
99
from django.http import HttpResponse
10+
from django.utils.html import escape
1011

1112
import changelog
1213

@@ -33,7 +34,7 @@ def release(request, version=None):
3334
entries = dict((entry.version, entry) for entry in log_entries)
3435
if version == None or version not in entries:
3536
version = log_entries[0].version
36-
entries[version].logentry = trac_links(entries[version].logentry.strip('\n'))
37+
entries[version].logentry = trac_links(escape(entries[version].logentry.strip('\n')))
3738

3839
code_coverage_url = None
3940
code_coverage_time = None

0 commit comments

Comments
 (0)