mirror of
https://github.com/csd4ni3l/loginween.git
synced 2026-01-01 04:23:48 +01:00
fix change username XSS
This commit is contained in:
5
app.py
5
app.py
@@ -166,7 +166,10 @@ def profile_external(username):
|
||||
def change_username():
|
||||
username = flask_login.current_user.id
|
||||
|
||||
new_username = request.form["new_username"]
|
||||
if request.form["new_username"] != html.escape(request.form["new_username"], quote=True):
|
||||
return "No XSS please"
|
||||
|
||||
new_username = html.escape(request.form["new_username"], quote=True)
|
||||
|
||||
cur = get_db().cursor()
|
||||
|
||||
|
||||
Reference in New Issue
Block a user