view website/issues/detectors/statusauditor.py @ 4577:528fe0a3af24

issue2550711 Fix XSS vulnerability when username contains HTML code. Thanks to Thomas Arendsen Hein for reporting and patch.
author Ralf Schlatterbeck <rsc@runtux.com>
date Thu, 05 Jan 2012 15:56:15 +0100
parents c2d0d3e9099d
children 0942fe89e82e
line wrap: on
line source

def preset_new(db, cl, nodeid, newvalues):
    """ Make sure the status is set on new issues"""

    if newvalues.has_key('status') and newvalues['status']:
        return

    new = db.status.lookup('new')
    newvalues['status'] = new


def init(db):
    # fire before changes are made
    db.issue.audit('create', preset_new)

Roundup Issue Tracker: http://roundup-tracker.org/