Skip to content

Commit eb88abc

Browse files
committed
Removed an instance of 'autoescape off' for submitted meeting session comments in a template, since it is not needed in practice, in order to avoid an XSS injection opportunity.
- Legacy-Id: 17322
1 parent e2eb199 commit eb88abc

File tree

1 file changed

+0
-2
lines changed

1 file changed

+0
-2
lines changed

ietf/secr/templates/includes/sessions_request_view.html

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,5 @@
3333
<tr class="row1">
3434
<td>People who must be present:</td>
3535
<td>{% if session.bethere %}<ul>{% for person in session.bethere %}<li>{{ person }}</li>{% endfor %}</ul>{% else %}<i>None</i>{% endif %}</td>
36-
{% autoescape off %}
3736
<tr class="row2"><td>Special Requests:</td><td>{{ session.comments }}</td></tr>
38-
{% endautoescape %}
3937
</table>

0 commit comments

Comments
 (0)