also escape HTML in the file name

This commit is contained in:
Mike Bonnet 2009-02-02 14:11:54 -05:00
parent d6a8bb9322
commit f1a36d48b5

View file

@ -163,7 +163,7 @@
</tr>
#for $file in $files
<tr class="$util.rowToggle($self)">
<td><a href="fileinfo?rpmID=$rpm.id&amp;filename=$urllib.quote($file.name)">$file.name</a></td><td>$file.size</td>
<td><a href="fileinfo?rpmID=$rpm.id&amp;filename=$urllib.quote($file.name)">$util.escapeHTML($file.name)</a></td><td>$file.size</td>
</tr>
#end for
</table>