summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorJean-Philippe Lang <jp_lang@yahoo.fr>2008-12-12 16:01:35 +0000
committerJean-Philippe Lang <jp_lang@yahoo.fr>2008-12-12 16:01:35 +0000
commit29f364f63cbc44924c79ceeb887c4ae81a1f7c71 (patch)
tree214687264926246dd52c3d5912b00068a17c5218
parentb21b6c365cc1f058207490d924d4c804843464a8 (diff)
downloadredmine-29f364f63cbc44924c79ceeb887c4ae81a1f7c71.tar.gz
redmine-29f364f63cbc44924c79ceeb887c4ae81a1f7c71.zip
Escape back_url field value (#2320).
git-svn-id: svn+ssh://rubyforge.org/var/svn/redmine/trunk@2125 e93f8b46-1217-0410-a6f0-8f06a7374b81
-rw-r--r--app/helpers/application_helper.rb3
1 files changed, 2 insertions, 1 deletions
diff --git a/app/helpers/application_helper.rb b/app/helpers/application_helper.rb
index cb0233fd6..56db00855 100644
--- a/app/helpers/application_helper.rb
+++ b/app/helpers/application_helper.rb
@@ -18,6 +18,7 @@
require 'coderay'
require 'coderay/helpers/file_type'
require 'forwardable'
+require 'cgi'
module ApplicationHelper
include Redmine::WikiFormatting::Macros::Definitions
@@ -525,7 +526,7 @@ module ApplicationHelper
def back_url_hidden_field_tag
back_url = params[:back_url] || request.env['HTTP_REFERER']
- hidden_field_tag('back_url', back_url) unless back_url.blank?
+ hidden_field_tag('back_url', CGI.escape(back_url)) unless back_url.blank?
end
def check_all_links(form_name)