HTML escape record values

This commit is contained in:
Jamie Cameron
2016-12-06 20:35:06 -08:00
parent 3bee204db2
commit e43ec7e4c0

View File

@@ -20,15 +20,15 @@ if ($type eq 'record') {
$p->{'newvalues'}) {
return &text("log_${action}_record_v",
$text{"type_$p->{'type'}"},
"<tt>$p->{'name'}</tt>",
"<tt>$object</tt>",
"<tt>$p->{'newvalues'}</tt>");
"<tt>".&html_escape($p->{'name'})."</tt>",
"<tt>".&html_escape($object)."</tt>",
"<tt>".&html_escape($p->{'newvalues'})."</tt>");
}
else {
return &text("log_${action}_record",
$text{"type_$p->{'type'}"},
"<tt>$p->{'name'}</tt>",
"<tt>$object</tt>");
"<tt>".&html_escape($p->{'name'})."</tt>",
"<tt>".&html_escape($object)."</tt>");
}
}
}