From 0f909007d8e93e1993217f70ca8f16ad4a12f2c5 Mon Sep 17 00:00:00 2001 From: Maxim Lebedev Date: Wed, 8 Nov 2023 07:43:38 +0600 Subject: [PATCH] :lipstick: Unsafe renders page content --- web/template/page.qtpl | 2 +- web/template/page.qtpl.go | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/web/template/page.qtpl b/web/template/page.qtpl index 1c0175e..b5fdf7d 100644 --- a/web/template/page.qtpl +++ b/web/template/page.qtpl @@ -36,6 +36,6 @@ func NewPage(base BaseOf, page *domain.Page) Page { {% endfunc %} {% func (p Page) Body() %} -

{%z p.page.Content %}

+

{%z= p.page.Content %}

{% endfunc %} {% endstripspace %} diff --git a/web/template/page.qtpl.go b/web/template/page.qtpl.go index a6f4cce..67fea97 100644 --- a/web/template/page.qtpl.go +++ b/web/template/page.qtpl.go @@ -124,7 +124,7 @@ func (p Page) StreamBody(qw422016 *qt422016.Writer) { //line web/template/page.qtpl:38 qw422016.N().S(`

`) //line web/template/page.qtpl:39 - qw422016.E().Z(p.page.Content) + qw422016.N().Z(p.page.Content) //line web/template/page.qtpl:39 qw422016.N().S(`

`) //line web/template/page.qtpl:40