Homec4science

Properly escape user-defined values to avoid XSS.

Authored by Jerome Caffaro <jerome.caffaro@cern.ch> on Sep 26 2008, 08:56.

Description

Properly escape user-defined values to avoid XSS.

Also fixes links to modify/delete alert when alert name include quotes.
Also limited alert name to 30 chars, as it is defined in the DB.

Details

Event Timeline

Jerome Caffaro <jerome.caffaro@cern.ch> committed R3600:3bf297a38c8c: Properly escape user-defined values to avoid XSS. (authored by Jerome Caffaro <jerome.caffaro@cern.ch>).Sep 26 2008, 08:56