From c57c6b16c74f7f570c6460be8131da62ea36e237 Mon Sep 17 00:00:00 2001 From: Ted Trask Date: Thu, 15 Jan 2009 21:44:39 +0000 Subject: Modified html.lua and viewlibrary.lua and all html files to html_escape variables before displaying them. git-svn-id: svn://svn.alpinelinux.org/acf/samba/trunk@1678 ab2d0c66-481e-0410-8bed-d214d4d58bed --- samba-editshare-html.lsp | 2 +- samba-join-html.lsp | 2 +- samba-listshares-html.lsp | 10 +++++----- 3 files changed, 7 insertions(+), 7 deletions(-) diff --git a/samba-editshare-html.lsp b/samba-editshare-html.lsp index aa67e11..e1d327a 100644 --- a/samba-editshare-html.lsp +++ b/samba-editshare-html.lsp @@ -2,7 +2,7 @@ require("viewfunctions") %> -

<%= form.label %>

+

<%= html.html_escape(form.label) %>

<% form.action = page_info.script .. page_info.prefix .. page_info.controller .. "/" .. page_info.action local order = {"name", "valid", "comment", "path", "browseable", "guest", "printable", "writable"} diff --git a/samba-join-html.lsp b/samba-join-html.lsp index 12afb09..d26a41b 100644 --- a/samba-join-html.lsp +++ b/samba-join-html.lsp @@ -8,7 +8,7 @@ require("viewfunctions") viewlibrary.dispatch_component("status") end %> -

<%= form.label %>

+

<%= html.html_escape(form.label) %>

<% form.action = page_info.script .. page_info.prefix .. page_info.controller .. "/" .. page_info.action local order = {"domain", "login", "password"} diff --git a/samba-listshares-html.lsp b/samba-listshares-html.lsp index 67af4c8..7489601 100644 --- a/samba-listshares-html.lsp +++ b/samba-listshares-html.lsp @@ -27,9 +27,9 @@ No Shares Found <%= html.link{value=page_info.script..page_info.prefix..page_info.controller.."/deleteshare?name="..share.name, label="Delete "} %> <% end %> - <%= share.name %> - <%= share.path %> - <%= share.comment %> + <%= html.html_escape(share.name) %> + <%= html.html_escape(share.path) %> + <%= html.html_escape(share.comment) %> <% end %> @@ -37,8 +37,8 @@ No Shares Found <% if viewlibrary and viewlibrary.dispatch_component and session.permissions.samba.createshare then %>

Create new share

-
- + +
<% end %> -- cgit v1.2.3