From: Junio C Hamano Date: Wed, 07 Mar 2007 01:40:28 GMT Subject: Re: [PATCH] gitweb: Don't escape attributes in CGI.pm HTML methods Message-ID: <7vk5xtn84z.fsf@assigned-by-dhcp.cox.net> In-Reply-To: <200703070221.25519.jnareb@gmail.com> Jakub Narebski writes: > There is no need to escape HTML tag's attributes in CGI.pm > HTML methods (like CGI::a()), because CGI.pm does attribute > escaping automatically. > > Explanation: > $cgi->a({ ... -attribute => atribute_value }, tag_contents) > is translated to > tag_contents > The rules for escaping attribute values (which are string contents) are > different. For example you have to take care about escaping embedded '"' > and "'" characters; CGI::a() does that for us automatically. > > CGI::a() cannot HTML escape tag contents automatically; we might want to > write > some bold text > for example. So we have to esc_html (or esc_path) if needed. > > Signed-off-by: Jakub Narebski > --- > Junio C Hamano wrote: >> Jakub Narebski writes: >> >>> In short: escape tag contents if needed, do not escape attrbure values. >> >> I trust a patch from you will follow shortly? > > Here it is. I hope I found everything. > > Commit message is bit long, so you can cut it to first sentence only > (or even only to title/subject). Thanks. I think your explanation in the log message has the right amount of details and keeping it there would help people who would want to later touch the code.