2DU před 9 roky
rodič
revize
15502f0429
1 změnil soubory, kde provedl 6 přidání a 0 odebrání
  1. 6 0
      app.py

+ 6 - 0
app.py

@@ -688,6 +688,9 @@ def reraw(name = None, number = None):
     rows = curs.fetchall()
     if(rows):
         enddata = re.sub("\n", '<br>', rows[0]['data'])
+        enddata = re.sub('<', '&lt;', enddata)
+        enddata = re.sub('>', '&gt;', enddata)
+        enddata = re.sub('"', '&quot;', enddata)
         return render_template('index.html', title = name, logo = data['name'], page = parse.quote(name), data = enddata, license = data['license'])
     else:
         return render_template('index.html', title = name, logo = data['name'], page = parse.quote(name), data = '<br>문서 없음', license = data['license'])
@@ -698,6 +701,9 @@ def raw(name = None):
     rows = curs.fetchall()
     if(rows):
         enddata = re.sub("\n", '<br>', rows[0]['data'])
+        enddata = re.sub('<', '&lt;', enddata)
+        enddata = re.sub('>', '&gt;', enddata)
+        enddata = re.sub('"', '&quot;', enddata)
         return render_template('index.html', title = name, logo = data['name'], page = parse.quote(name), data = enddata, license = data['license'], tn = 7)
     else:
         return render_template('index.html', title = name, logo = data['name'], page = parse.quote(name), data = '문서 없음', license = data['license'], tn = 7)