From: Jeff King Date: Tue, 06 Mar 2007 09:39:17 GMT Subject: Re: [PATCH] gitweb: Change to use explicitly function call cgi->escapHTML() Message-ID: <20070306093917.GA1761@coredump.intra.peff.net> In-Reply-To: <8fe92b430703060134l14fffcc4rbece3c2071c56422@mail.gmail.com> On Tue, Mar 06, 2007 at 10:34:32AM +0100, Jakub Narebski wrote: > >Regardless of the recent xhtml+html vs html discussion, I think > >this is probably a sane change. Comments? > Good (although a bit magic) solution. Ack, FWIW. I think this should do the same, and is perhaps less magic (or maybe more, depending on your perspective). -Peff -- >8 -- diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl index 653ca3c..5d1d8cf 100755 --- a/gitweb/gitweb.perl +++ b/gitweb/gitweb.perl @@ -17,6 +17,7 @@ use Fcntl ':mode'; use File::Find qw(); use File::Basename qw(basename); binmode STDOUT, ':utf8'; +CGI::autoEscape(1); BEGIN { CGI->compile() if $ENV{MOD_PERL};