From: Junio C Hamano Date: Tue, 06 Mar 2007 10:58:37 GMT Subject: Re: [PATCH] gitweb: Change to use explicitly function call cgi->escapHTML() Message-ID: <7vps7mprj6.fsf@assigned-by-dhcp.cox.net> In-Reply-To: <20070306105629.GA13285@coredump.intra.peff.net> Jeff King writes: > On Tue, Mar 06, 2007 at 02:53:07AM -0800, Junio C Hamano wrote: > >> But then you are letting _other_ mod_perl users to affect your >> behaviour, aren't you? "sub autoEscape" does this: > > Yes (but I don't know how mod_perl works, and I haven't been able to > find a simple answer by skimming the docs). > >> If we worry about mod_perl (provided if $CGI::Q is shared across >> mod_perl users), I suspect we would need to be a bit more >> paranoid, perhaps like this, woudln't we? >> [...] >> +$cgi->autoEscape(1); > > That rebreaks the original problem, though. Sorry, what I meant to say was on top of Li's patch.