From: Jakub Narebski Date: Tue, 06 Mar 2007 13:23:17 GMT Subject: Re: [PATCH] gitweb: Change to use explicitly function call cgi->escapHTML() Message-ID: <200703061423.18417.jnareb@gmail.com> In-Reply-To: <7vzm6qps51.fsf@assigned-by-dhcp.cox.net> Junio C Hamano wrote: > Speaking of -title, I see "sub git_project_list_body" does this: > >     $cgi->a({ ... -title => $pr->{'descr_long'}}, esc_html($pr->{'descr'})); >          > which seems inconsistent with the earlier quoted $fullname > handling (unless $pr->{'descr_long'} is already quoted and $pr->{'descr'} > is not, which I find highly unlikely). CGI::a() subroutine automatically quotes properly _attribute_ values, but it does not (and it should not) quote _contents_ of a tag. So the above code is correct. -- Jakub Narebski Poland