From 1c7f0f184aa7407a97f0d81a6954007bab66e6eb Mon Sep 17 00:00:00 2001 From: Ted Trask Date: Thu, 15 Jan 2009 21:44:39 +0000 Subject: Modified html.lua and viewlibrary.lua and all html files to html_escape variables before displaying them. git-svn-id: svn://svn.alpinelinux.org/acf/dnscache/trunk@1678 ab2d0c66-481e-0410-8bed-d214d4d58bed --- dnscache-editdomain-html.lsp | 2 +- dnscache-listdomains-html.lsp | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/dnscache-editdomain-html.lsp b/dnscache-editdomain-html.lsp index 1380add..e3cd759 100644 --- a/dnscache-editdomain-html.lsp +++ b/dnscache-editdomain-html.lsp @@ -9,7 +9,7 @@ io.write("") --]] %> -

<%= form.label %>

+

<%= html.html_escape(form.label) %>

<% form.action = page_info.script .. page_info.prefix .. page_info.controller .. "/" .. page_info.action form.value.domain.readonly = true diff --git a/dnscache-listdomains-html.lsp b/dnscache-listdomains-html.lsp index 634b733..2c3cfd2 100644 --- a/dnscache-listdomains-html.lsp +++ b/dnscache-listdomains-html.lsp @@ -27,7 +27,7 @@ io.write("") io.write(html.link{value = "deletedomain?domain=" .. domain, label="Delete " }) end %> - <%= domain %> + <%= html.html_escape(domain) %> <% end %> -- cgit v1.2.3