]> source.dussan.org Git - redmine.git/commitdiff
Escape back_url field value (#2320).
authorJean-Philippe Lang <jp_lang@yahoo.fr>
Fri, 12 Dec 2008 16:01:35 +0000 (16:01 +0000)
committerJean-Philippe Lang <jp_lang@yahoo.fr>
Fri, 12 Dec 2008 16:01:35 +0000 (16:01 +0000)
git-svn-id: svn+ssh://rubyforge.org/var/svn/redmine/trunk@2125 e93f8b46-1217-0410-a6f0-8f06a7374b81

app/helpers/application_helper.rb

index cb0233fd64e963e8a53bca8f5f1d420f9d7de78f..56db008553c3ec0c6cbf6b710ac855c066db0552 100644 (file)
@@ -18,6 +18,7 @@
 require 'coderay'
 require 'coderay/helpers/file_type'
 require 'forwardable'
+require 'cgi'
 
 module ApplicationHelper
   include Redmine::WikiFormatting::Macros::Definitions
@@ -525,7 +526,7 @@ module ApplicationHelper
 
   def back_url_hidden_field_tag
     back_url = params[:back_url] || request.env['HTTP_REFERER']
-    hidden_field_tag('back_url', back_url) unless back_url.blank?
+    hidden_field_tag('back_url', CGI.escape(back_url)) unless back_url.blank?
   end
 
   def check_all_links(form_name)