Skip to content

HTTPS clone URL

Subversion checkout URL

You can clone with HTTPS or Subversion.

Download ZIP
Browse files

Fixed #2761 -- Apply escaping to values in form checkbox attributes.

git-svn-id: http://code.djangoproject.com/svn/django/trunk@3775 bcc190cf-cafb-0310-a4f2-bffc1f526a37
  • Loading branch information...
commit 31d764cadfa52e851db9eccb0e84b567ff4c0579 1 parent e947fb2
Malcolm Tredinnick malcolmt authored
Showing with 2 additions and 2 deletions.
  1. +2 −2 django/forms/__init__.py
4 django/forms/__init__.py
View
@@ -639,8 +639,8 @@ def render(self, data):
checked_html = ' checked="checked"'
field_name = '%s%s' % (self.field_name, value)
output.append('<li><input type="checkbox" id="%s" class="v%s" name="%s"%s /> <label for="%s">%s</label></li>' % \
- (self.get_id() + value , self.__class__.__name__, field_name, checked_html,
- self.get_id() + value, choice))
+ (self.get_id() + escape(value), self.__class__.__name__, field_name, checked_html,
+ self.get_id() + escape(value), choice))
output.append('</ul>')
return '\n'.join(output)
Please sign in to comment.
Something went wrong with that request. Please try again.