Files
@ 48b9fdef5e7f
Branch filter:
Location: kallithea/dev_requirements.txt
48b9fdef5e7f
223 B
text/plain
repo_groups: extra escape of names when used in select drop-downs
The lack of escaping could be a problem *if* it was possible to create repo
groups with dangerous names.
This was seen for example when specifying parent group of repos and repo
groups.
We want to keep groups_choices as HTML literals so paths can use » as
separator.
The lack of escaping could be a problem *if* it was possible to create repo
groups with dangerous names.
This was seen for example when specifying parent group of repos and repo
groups.
We want to keep groups_choices as HTML literals so paths can use » as
separator.