Skip to content

HTTPS clone URL

Subversion checkout URL

You can clone with
or
.
Download ZIP
Browse files

Removed mark_safe from the saved request path on the admin login form…

…. This prevents a potential XSS attack. Formal announcement will be forthcoming.

git-svn-id: http://code.djangoproject.com/svn/django/trunk@7521 bcc190cf-cafb-0310-a4f2-bffc1f526a37
  • Loading branch information...
commit 41635d2176f7a950498b020f335232ad9f734279 1 parent 4880ba3
@freakboy3742 freakboy3742 authored
Showing with 1 addition and 1 deletion.
  1. +1 −1  django/contrib/admin/views/decorators.py
View
2  django/contrib/admin/views/decorators.py
@@ -29,7 +29,7 @@ def _display_login_form(request, error_message=''):
post_data = _encode_post_data({})
return render_to_response('admin/login.html', {
'title': _('Log in'),
- 'app_path': mark_safe(request.path),
+ 'app_path': request.path,
'post_data': post_data,
'error_message': error_message
}, context_instance=template.RequestContext(request))
Please sign in to comment.
Something went wrong with that request. Please try again.