Skip to content
This repository

HTTPS clone URL

Subversion checkout URL

You can clone with HTTPS or Subversion.

Download ZIP
Browse code

Removed mark_safe from the saved request path on the admin login form…

…. This prevents a potential XSS attack. Formal announcement will be forthcoming.

git-svn-id: http://code.djangoproject.com/svn/django/trunk@7521 bcc190cf-cafb-0310-a4f2-bffc1f526a37
  • Loading branch information...
commit 41635d2176f7a950498b020f335232ad9f734279 1 parent 4880ba3
Russell Keith-Magee authored
2  django/contrib/admin/views/decorators.py
@@ -29,7 +29,7 @@ def _display_login_form(request, error_message=''):
29 29
         post_data = _encode_post_data({})
30 30
     return render_to_response('admin/login.html', {
31 31
         'title': _('Log in'),
32  
-        'app_path': mark_safe(request.path),
  32
+        'app_path': request.path,
33 33
         'post_data': post_data,
34 34
         'error_message': error_message
35 35
     }, context_instance=template.RequestContext(request))

0 notes on commit 41635d2

Please sign in to comment.
Something went wrong with that request. Please try again.