Ignore:
Timestamp:
6 Apr 2016, 11:17:16 (9 years ago)
Author:
Henrik Bettermann
Message:

Escape HTML in Logfiles when displayed in Browser.

When logfiles are displayed in datacenter, included
HTML tags should show up as tags and not be rendered
by the browser. We therefore cgi.escape logfile
contents.

See r13495 and r13496.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • main/waeup.ikoba/trunk/src/waeup/ikoba/browser/pages.py

    r13806 r13808  
    2020# XXX: All csv ops should move to a dedicated module soon
    2121import unicodecsv as csv
     22import cgi
    2223import grok
    2324import os
     
    15611562            return
    15621563        try:
    1563             self.result = ''.join(
    1564                 self.context.queryLogfiles(logname, query))
     1564            self.result = cgi.escape(
     1565                ''.join(self.context.queryLogfiles(logname, query)))
    15651566        except ValueError:
    15661567            self.flash(_('Invalid search expression.'), type='danger')
Note: See TracChangeset for help on using the changeset viewer.