Re: [PATCH] gitweb: Change to use explicitly function call cgi->escapHTML()
- From
Jeff King <peff@peff.net>
- Date
- Mar 6, 2007, 11:07 UTC
- Message-ID
- <20070306110754.GA13470@coredump.intra.peff.net>
- In-Reply-To
- <7vlkiapr70.fsf@assigned-by-dhcp.cox.net>
On Tue, Mar 06, 2007 at 03:05:55AM -0800, Junio C Hamano wrote:
Show 8 quoted lines
> > Ah, I understand your point now. Yes, if other mod_perl CGIs can impact
> > the value, then we should definitely set it explicitly, as per your
> > patch (and we should use Li's patch for safety, then, not mine).
>
> Reading "sub autoEscape", "sub escapeHTML" and "sub
> self_or_default" again, I think other people cannot affect the
> value of our $cgi->{'escape'} by calling autoEscape, so what I
> said is probably bogus. Let's use Li's original patch.Er, sorry, yes, I just accidentally agreed with your bogosity (while figuring out what you originally meant, I forgot which CGI we were talking about!). So I agree, Li's original is sufficient. Sorry for the noise. :)
-Peff