git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] gitweb: Don't escape attributes in CGI.pm HTML methods

From
Jakub Narebski <jnareb@gmail.com>
Date
Mar 7, 2007, 01:21 UTC
Message-ID
<200703070221.25519.jnareb@gmail.com>
In-Reply-To
<7vvehdnaib.fsf@assigned-by-dhcp.cox.net>

There is no need to escape HTML tag's attributes in CGI.pm HTML methods (like CGI::a()), because CGI.pm does attribute escaping automatically.

Explanation:
  $cgi->a({ ... -attribute => atribute_value }, tag_contents)
is translated to
  <a ... attribute="attribute_value">tag_contents</a>
The rules for escaping attribute values (which are string contents) are
different. For example you have to take care about escaping embedded '"'
and "'" characters; CGI::a() does that for us automatically.
CGI::a() cannot HTML escape tag contents automatically; we might want to
write
  <a href="URL">some <b>bold</b> text</a>
for example. So we have to esc_html (or esc_path) if needed.
Signed-off-by: Jakub Narebski <jnareb@gmail.com>
---
Junio C Hamano wrote:
Show 5 quoted lines
> Jakub Narebski <jnareb@gmail.com> writes:
> 
>> In short: escape tag contents if needed, do not escape attrbure values.
> 
> I trust a patch from you will follow shortly?
Here it is. I hope I found everything.

Commit message is bit long, so you can cut it to first sentence only (or even only to title/subject).

 gitweb/gitweb.perl |    6 +++---
 1 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl
index 653ca3c..ea58946 100755
--- a/gitweb/gitweb.perl
+++ b/gitweb/gitweb.perl
@@ -1974,17 +1974,17 @@ sub git_print_page_path {
 			$fullname .= ($fullname ? '/' : '') . $dir;
 			print $cgi->a({-href => href(action=>"tree", file_name=>$fullname,
 			                             hash_base=>$hb),
-			              -title => esc_html($fullname)}, esc_path($dir));
+			              -title => $fullname}, esc_path($dir));
 			print " / ";
 		}
 		if (defined $type && $type eq 'blob') {
 			print $cgi->a({-href => href(action=>"blob_plain", file_name=>$file_name,
 			                             hash_base=>$hb),
-			              -title => esc_html($name)}, esc_path($basename));
+			              -title => $name}, esc_path($basename));
 		} elsif (defined $type && $type eq 'tree') {
 			print $cgi->a({-href => href(action=>"tree", file_name=>$file_name,
 			                             hash_base=>$hb),
-			              -title => esc_html($name)}, esc_path($basename));
+			              -title => $name}, esc_path($basename));
 			print " / ";
 		} else {
 			print esc_path($basename);
-- 
1.5.0.2
Previous: Junio C HamanoNext: Junio C Hamano
Message 20 of 21 in “gitweb: Change to use explicitly function call cgi->escapHTML()”
  1. gitweb: Change to use explicitly function call cgi->escapHTML()Li Yang, Mar 6, 2007
  2. Junio C HamanoMar 6, 2007
  3. Jakub NarebskiMar 6, 2007
  4. Jeff KingMar 6, 2007
  5. Junio C HamanoMar 6, 2007
  6. Li Yang-r58472Mar 6, 2007
  7. Jeff KingMar 6, 2007
  8. Junio C HamanoMar 6, 2007
  9. Jeff KingMar 6, 2007
  10. Junio C HamanoMar 6, 2007
  11. Jeff KingMar 6, 2007
  12. Junio C HamanoMar 6, 2007
  13. Jeff KingMar 6, 2007
  14. Li Yang-r58472Mar 6, 2007
  15. Junio C HamanoMar 6, 2007
  16. Jakub NarebskiMar 6, 2007
  17. Junio C HamanoMar 6, 2007
  18. Jakub NarebskiMar 7, 2007
  19. Junio C HamanoMar 7, 2007
  20. gitweb: Don't escape attributes in CGI.pm HTML methodsJakub Narebski, Mar 7, 2007
  21. Junio C HamanoMar 7, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.