From: Jean-Philippe Lang Date: Fri, 12 Dec 2008 16:01:35 +0000 (+0000) Subject: Escape back_url field value (#2320). X-Git-Tag: 0.9.0~882 X-Git-Url: https://source.dussan.org/?a=commitdiff_plain;h=29f364f63cbc44924c79ceeb887c4ae81a1f7c71;p=redmine.git Escape back_url field value (#2320). git-svn-id: svn+ssh://rubyforge.org/var/svn/redmine/trunk@2125 e93f8b46-1217-0410-a6f0-8f06a7374b81 --- diff --git a/app/helpers/application_helper.rb b/app/helpers/application_helper.rb index cb0233fd6..56db00855 100644 --- a/app/helpers/application_helper.rb +++ b/app/helpers/application_helper.rb @@ -18,6 +18,7 @@ require 'coderay' require 'coderay/helpers/file_type' require 'forwardable' +require 'cgi' module ApplicationHelper include Redmine::WikiFormatting::Macros::Definitions @@ -525,7 +526,7 @@ module ApplicationHelper def back_url_hidden_field_tag back_url = params[:back_url] || request.env['HTTP_REFERER'] - hidden_field_tag('back_url', back_url) unless back_url.blank? + hidden_field_tag('back_url', CGI.escape(back_url)) unless back_url.blank? end def check_all_links(form_name)