From: joey <joey@0fa5a96a-9a0e-0410-b3b2-a0fd24251071>
Date: Wed, 6 Sep 2006 20:02:12 +0000 (+0000)
Subject: escaping fix from Emanuele Aina
X-Git-Tag: 1.25~31
X-Git-Url: http://git.tremily.us/?a=commitdiff_plain;h=1f26347379fd646e75302f32cf3411fb09cef5e4;p=ikiwiki.git

escaping fix from Emanuele Aina
---

diff --git a/IkiWiki/CGI.pm b/IkiWiki/CGI.pm
index 6e1efbd69..be06db49c 100644
--- a/IkiWiki/CGI.pm
+++ b/IkiWiki/CGI.pm
@@ -81,7 +81,7 @@ sub cgi_recentchanges ($) { #{{{
 	my $changelog=[rcs_recentchanges(100)];
 	foreach my $change (@$changelog) {
 		$change->{when} = concise(ago($change->{when}));
-		$change->{user} = htmllink("", "", $change->{user}, 1);
+		$change->{user} = htmllink("", "", escapeHTML($change->{user}), 1);
 		$change->{pages} = [
 			map {
 				$_->{link} = htmllink("", "", $_->{page}, 1);
diff --git a/templates/recentchanges.tmpl b/templates/recentchanges.tmpl
index f927cf62f..726e52f64 100644
--- a/templates/recentchanges.tmpl
+++ b/templates/recentchanges.tmpl
@@ -30,7 +30,7 @@
 <TMPL_LOOP NAME="CHANGELOG">
 	<!-- <TMPL_VAR NAME="REV"> -->
 	<tr class="changeinfo">
-		<td class="changeinfo"><TMPL_VAR NAME="USER" ESCAPE="HTML"></td>
+		<td class="changeinfo"><TMPL_VAR NAME="USER"></td>
 		<td class="changetime"><TMPL_VAR NAME="WHEN"></td>
 		<td class="changeinfo">
 		<TMPL_LOOP NAME="PAGES">