From 03a032ff1e55e257cb6403fe0fb3f4885cbcf42c Mon Sep 17 00:00:00 2001 From: zhengxie Date: Mon, 6 Jun 2016 14:48:01 +0800 Subject: [PATCH] Escape group name in notice --- seahub/notifications/models.py | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/seahub/notifications/models.py b/seahub/notifications/models.py index 2f535a8945..252193bf42 100644 --- a/seahub/notifications/models.py +++ b/seahub/notifications/models.py @@ -567,7 +567,8 @@ class UserNotification(models.Model): msg = _(u"%(user)s posted a new discussion in %(group_name)s.") % { 'href': reverse('group_discuss', args=[group.id]), 'user': escape(email2nickname(msg_from)), - 'group_name': group.group_name} + 'group_name': escape(group.group_name) + } return msg def format_group_message_detail(self): @@ -613,7 +614,7 @@ class UserNotification(models.Model): 'user_profile': reverse('user_profile', args=[username]), 'username': username, 'href': reverse('group_members', args=[group_id]), - 'group_name': group.group_name, + 'group_name': escape(group.group_name), 'join_request_msg': escape(join_request_msg), } return msg @@ -642,8 +643,7 @@ class UserNotification(models.Model): 'user_profile': reverse('user_profile', args=[group_staff]), 'group_staff': group_staff, 'href': reverse('group_info', args=[group_id]), - 'group_name': group.group_name, - } + 'group_name': escape(group.group_name)} return msg ########## handle signals