From afcd120c1c5b8d839820259c9d8b488e994fcffe Mon Sep 17 00:00:00 2001 From: Ted Trask Date: Thu, 15 Jan 2009 21:44:39 +0000 Subject: Modified html.lua and viewlibrary.lua and all html files to html_escape variables before displaying them. git-svn-id: svn://svn.alpinelinux.org/acf/openssl/trunk@1678 ab2d0c66-481e-0410-8bed-d214d4d58bed --- openssl-html.lsp | 30 +++++++++++++++--------------- 1 file changed, 15 insertions(+), 15 deletions(-) (limited to 'openssl-html.lsp') diff --git a/openssl-html.lsp b/openssl-html.lsp index 4258171..bd2ed7e 100644 --- a/openssl-html.lsp +++ b/openssl-html.lsp @@ -18,7 +18,7 @@ io.write(html.cfe_unpack(view)) <% displaycommandresults({"approve", "deleterequest", "deletemyrequest", "renewcert", "requestrenewcert", "revoke", "deletecert"}, session) %> -

Pending certificate requests<% if view.value.user then%> for <%= view.value.user.value %><% end %>

+

Pending certificate requests<% if view.value.user then%> for <%= html.html_escape(view.value.user.value) %><% end %>

<% if not view.value.pending or #view.value.pending.value == 0 then %> No certificates pending <% else %> @@ -47,9 +47,9 @@ io.write(html.cfe_unpack(view)) io.write(html.link{value="deletemyrequest?request="..request.name, label="Delete "}) end %> - <%= request.user %> - <%= request.certtype %> - <%= request.commonName %> + <%= html.html_escape(request.user) %> + <%= html.html_escape(request.certtype) %> + <%= html.html_escape(request.commonName) %> <% end %> @@ -74,7 +74,7 @@ else approved = view.value.approved.value end %> -

Approved certificate requests<% if view.value.user then%> for <%= view.value.user.value %><% end %>

+

Approved certificate requests<% if view.value.user then%> for <%= html.html_escape(view.value.user.value) %><% end %>

<% if #approved == 0 then %> No certificates approved <% else %> @@ -111,18 +111,18 @@ end %> <%= html.link{value="deletecert?cert="..cert.name, label="Delete "} %> <% end %> - <%= cert.user %> - <%= cert.certtype %> - <%= cert.commonName %> - <%= tostring(tonumber('0x'..cert.serial)) %> - <%= cert.enddate %> + <%= html.html_escape(cert.user) %> + <%= html.html_escape(cert.certtype) %> + <%= html.html_escape(cert.commonName) %> + <%= html.html_escape(tostring(tonumber('0x'..cert.serial))) %> + <%= html.html_escape(cert.enddate) %> <% end %> <% end %> -

Revoked certificates<% if view.value.user then%> for <%= view.value.user.value %><% end %>

+

Revoked certificates<% if view.value.user then%> for <%= html.html_escape(view.value.user.value) %><% end %>

<% if #revoked == 0 then %> No certificates revoked <% else %> @@ -150,10 +150,10 @@ end %> <%= html.link{value="deletecert?cert="..cert.name, label="Delete "} %> <% end %> - <%= cert.user %> - <%= cert.certtype %> - <%= cert.commonName %> - <%= tostring(tonumber('0x'..cert.serial)) %> + <%= html.html_escape(cert.user) %> + <%= html.html_escape(cert.certtype) %> + <%= html.html_escape(cert.commonName) %> + <%= html.html_escape(tostring(tonumber('0x'..cert.serial))) %> <% end %> -- cgit v1.2.3