mirror of
https://github.com/csd4ni3l/loginween.git
synced 2026-01-01 04:23:48 +01:00
fix change username XSS
This commit is contained in:
5
app.py
5
app.py
@@ -166,7 +166,10 @@ def profile_external(username):
|
|||||||
def change_username():
|
def change_username():
|
||||||
username = flask_login.current_user.id
|
username = flask_login.current_user.id
|
||||||
|
|
||||||
new_username = request.form["new_username"]
|
if request.form["new_username"] != html.escape(request.form["new_username"], quote=True):
|
||||||
|
return "No XSS please"
|
||||||
|
|
||||||
|
new_username = html.escape(request.form["new_username"], quote=True)
|
||||||
|
|
||||||
cur = get_db().cursor()
|
cur = get_db().cursor()
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user