Fix escaping for login page

pull/598/head
Omar Roth 6 years ago
parent 3be1c9261f
commit fcf377d26b
No known key found for this signature in database
GPG Key ID: B8254FB7EC3D37F2

@ -32,7 +32,7 @@
<% end %> <% end %>
<% if password %> <% if password %>
<input name="password" type="hidden" value="<%= password %>"> <input name="password" type="hidden" value="<%= HTML.escape(password) %>">
<% else %> <% else %>
<label for="password"><%= translate(locale, "Password") %> :</label> <label for="password"><%= translate(locale, "Password") %> :</label>
<input required class="pure-input-1" name="password" type="password" placeholder="<%= translate(locale, "Password") %>"> <input required class="pure-input-1" name="password" type="password" placeholder="<%= translate(locale, "Password") %>">
@ -95,7 +95,7 @@
<% end %> <% end %>
<% if password %> <% if password %>
<input name="password" type="hidden" value="<%= password %>"> <input name="password" type="hidden" value="<%= HTML.escape(password) %>">
<% else %> <% else %>
<label for="password"><%= translate(locale, "Password") %> :</label> <label for="password"><%= translate(locale, "Password") %> :</label>
<input required class="pure-input-1" name="password" type="password" placeholder="<%= translate(locale, "Password") %>"> <input required class="pure-input-1" name="password" type="password" placeholder="<%= translate(locale, "Password") %>">

Loading…
Cancel
Save