Re: [PATCH] gitweb: Change to use explicitly function call cgi->escapHTML()
- From
Junio C Hamano <junkio@cox.net>
- Date
- Mar 6, 2007, 23:17 UTC
- Message-ID
- <7vzm6qm07l.fsf@assigned-by-dhcp.cox.net>
- In-Reply-To
- <200703061423.18417.jnareb@gmail.com>
Jakub Narebski <jnareb@gmail.com> writes:
Show 14 quoted lines
> Junio C Hamano wrote:
>
>> Speaking of -title, I see "sub git_project_list_body" does this:
>>
>> $cgi->a({ ... -title => $pr->{'descr_long'}}, esc_html($pr->{'descr'}));
>>
>> which seems inconsistent with the earlier quoted $fullname
>> handling (unless $pr->{'descr_long'} is already quoted and $pr->{'descr'}
>> is not, which I find highly unlikely).
>
> CGI::a() subroutine automatically quotes properly _attribute_ values,
> but it does not (and it should not) quote _contents_ of a tag.
>
> So the above code is correct.Sorry, you lost me... I am wondering what you mean by "automatically". Do you mean 'always'?
And if that is the case, shouldn't we drop esc_html() around $fullname here?
... For example, many places esc_html()
is used as the body of <a ...>$here</a> but some places it is
used as $cgi->a({ ... -title =>esc_html($fullname) }, esc_path($dir))as we do not have it around $pr->{'descr_long'} in the above?