From: Junio C Hamano Date: Tue, 06 Mar 2007 23:17:02 GMT Subject: Re: [PATCH] gitweb: Change to use explicitly function call cgi->escapHTML() Message-ID: <7vzm6qm07l.fsf@assigned-by-dhcp.cox.net> In-Reply-To: <200703061423.18417.jnareb@gmail.com> Jakub Narebski writes: > Junio C Hamano wrote: > >> Speaking of -title, I see "sub git_project_list_body" does this: >> >>     $cgi->a({ ... -title => $pr->{'descr_long'}}, esc_html($pr->{'descr'})); >>          >> which seems inconsistent with the earlier quoted $fullname >> handling (unless $pr->{'descr_long'} is already quoted and $pr->{'descr'} >> is not, which I find highly unlikely). > > CGI::a() subroutine automatically quotes properly _attribute_ values, > but it does not (and it should not) quote _contents_ of a tag. > > So the above code is correct. Sorry, you lost me... I am wondering what you mean by "automatically". Do you mean 'always'? And if that is the case, shouldn't we drop esc_html() around $fullname here? ... For example, many places esc_html() is used as the body of $here but some places it is used as $cgi->a({ ... -title =>esc_html($fullname) }, esc_path($dir)) as we do not have it around $pr->{'descr_long'} in the above?