Skip to content
Permalink
Browse files

escape invalid query params, fixes #1428

  • Loading branch information
namusyaka committed May 30, 2018
1 parent 5149dc9 commit 12786867d6faaceaec62c7c2cb5b0e2dc074d71a
Showing with 1 addition and 1 deletion.
  1. +1 −1 lib/sinatra/base.rb
@@ -78,7 +78,7 @@ def unlink?
def params
super
rescue Rack::Utils::ParameterTypeError, Rack::Utils::InvalidParameterError => e
raise BadRequest, "Invalid query parameters: #{e.message}"
raise BadRequest, "Invalid query parameters: #{Rack::Utils.escape_html(e.message)}"
end

private

0 comments on commit 1278686

Please sign in to comment.