Skip to content
This repository

HTTPS clone URL

Subversion checkout URL

You can clone with HTTPS or Subversion.

Download ZIP
Browse code

Improved [4180] to add HTML escaping on the primary-key value in the …

…error message

git-svn-id: http://code.djangoproject.com/svn/django/trunk@4181 bcc190cf-cafb-0310-a4f2-bffc1f526a37
  • Loading branch information...
commit 545ebf4395f24438c6ddc847f0794bfc83c6e934 1 parent 201704b
Adrian Holovaty authored December 07, 2006

Showing 1 changed file with 1 addition and 1 deletion. Show diff stats Hide diff stats

  1. 2  django/contrib/admin/views/main.py
2  django/contrib/admin/views/main.py
@@ -314,7 +314,7 @@ def change_stage(request, app_label, model_name, object_id):
314 314
     try:
315 315
         manipulator = model.ChangeManipulator(object_id)
316 316
     except model.DoesNotExist:
317  
-        raise Http404('%s object with primary key %r does not exist' % (model_name, object_id))
  317
+        raise Http404('%s object with primary key %r does not exist' % (model_name, escape(object_id)))
318 318
 
319 319
     if request.POST:
320 320
         new_data = request.POST.copy()

0 notes on commit 545ebf4

Please sign in to comment.
Something went wrong with that request. Please try again.