Ticket #2125: escaping.diff
File escaping.diff, 838 bytes (added by , 18 years ago) |
---|
-
django/forms/__init__.py
637 637 checked_html = ' checked="checked"' 638 638 field_name = '%s%s' % (self.field_name, value) 639 639 output.append('<li><input type="checkbox" id="%s" class="v%s" name="%s"%s /> <label for="%s">%s</label></li>' % \ 640 (self.get_id() + value , self.__class__.__name__, field_name, checked_html,641 self.get_id() + value, choice))640 (self.get_id() + escape(value) , self.__class__.__name__, escape(field_name), checked_html, 641 self.get_id() + escape(value), escape(choice))) 642 642 output.append('</ul>') 643 643 return '\n'.join(output) 644 644