Re: [PATCH] gitweb: Change to use explicitly function call cgi->escapHTML()
- From
Jeff King <peff@peff.net>
- Date
- Mar 6, 2007, 09:39 UTC
- Message-ID
- <20070306093917.GA1761@coredump.intra.peff.net>
- In-Reply-To
- <8fe92b430703060134l14fffcc4rbece3c2071c56422@mail.gmail.com>
On Tue, Mar 06, 2007 at 10:34:32AM +0100, Jakub Narebski wrote:
> >Regardless of the recent xhtml+html vs html discussion, I think > >this is probably a sane change. Comments? > Good (although a bit magic) solution. Ack, FWIW.
I think this should do the same, and is perhaps less magic (or maybe more, depending on your perspective).
-Peff
-- >8 --
diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl index 653ca3c..5d1d8cf 100755 --- a/gitweb/gitweb.perl +++ b/gitweb/gitweb.perl @@ -17,6 +17,7 @@ use Fcntl ':mode'; use File::Find qw(); use File::Basename qw(basename); binmode STDOUT, ':utf8'; +CGI::autoEscape(1); BEGIN { CGI->compile() if $ENV{MOD_PERL};