summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorville <ville@localhost>2010-05-07 18:17:38 +0000
committerville <ville@localhost>2010-05-07 18:17:38 +0000
commit5d96d6ff1fbf1e1081dc36e18b949e8c88506140 (patch)
treecfd1a18e090e3bb281537dfe5181f57be14694bc
parentbac3b6c995dcb41a8fee5d9dd35c934ac49d77f7 (diff)
downloadmarkup-validator-5d96d6ff1fbf1e1081dc36e18b949e8c88506140.zip
markup-validator-5d96d6ff1fbf1e1081dc36e18b949e8c88506140.tar.gz
markup-validator-5d96d6ff1fbf1e1081dc36e18b949e8c88506140.tar.bz2
Escape error messages also when showing source.
-rwxr-xr-xhtdocs/whatsnew.html8
-rw-r--r--share/templates/en_US/error_loop.tmpl2
2 files changed, 7 insertions, 3 deletions
diff --git a/htdocs/whatsnew.html b/htdocs/whatsnew.html
index 2901dbf..7c0f44d 100755
--- a/htdocs/whatsnew.html
+++ b/htdocs/whatsnew.html
@@ -1,5 +1,5 @@
-<!--#set var="revision" value="\$Id: whatsnew.html,v 1.99 2010-05-07 17:41:29 ville Exp $"
---><!--#set var="date" value="\$Date: 2010-05-07 17:41:29 $"
+<!--#set var="revision" value="\$Id: whatsnew.html,v 1.100 2010-05-07 18:17:37 ville Exp $"
+--><!--#set var="date" value="\$Date: 2010-05-07 18:17:37 $"
--><!--#set var="title" value="What's New at The W3C Markup Validation Service"
--><!--#set var="relroot" value="./"
--><!--#set var="feeds" value="1"
@@ -45,6 +45,10 @@
Bug fix: doctype override could place a malformed comment
in the modified document.
</li>
+ <li>
+ Bug fix: error messages were not properly HTML escaped when
+ "show source" was selected.
+ </li>
</ul>
</dd>
diff --git a/share/templates/en_US/error_loop.tmpl b/share/templates/en_US/error_loop.tmpl
index 0189ffc..5fa6bbc 100644
--- a/share/templates/en_US/error_loop.tmpl
+++ b/share/templates/en_US/error_loop.tmpl
@@ -5,7 +5,7 @@
<span class="err_type"><TMPL_IF NAME="err_type_info"><img src="images/info_icons/info.png" alt="Info" title="Info" /></TMPL_IF><TMPL_IF NAME="err_type_warn"><img src="images/info_icons/warning.png" alt="Warning" title="Warning" /></TMPL_IF><TMPL_IF NAME="err_type_err"><img src="images/info_icons/error.png" alt="Error" title="Error" /></TMPL_IF></span>
<TMPL_IF NAME="line"><em>Line <a href="#line-<TMPL_VAR NAME="line" ESCAPE="HTML">"><TMPL_VAR NAME="line" ESCAPE="HTML"></a><TMPL_IF NAME="char">,
Column <TMPL_VAR NAME="char" ESCAPE="HTML"></TMPL_IF></em>:</TMPL_IF>
- <span class="msg"><TMPL_VAR NAME="msg"></span>
+ <span class="msg"><TMPL_VAR NAME="msg" ESCAPE="HTML"></span>
<TMPL_IF NAME="uri">(<a href="<TMPL_VAR NAME="uri" ESCAPE="HTML">">explain...</a>)</TMPL_IF>
<TMPL_IF NAME="src"><pre><code class="input"><TMPL_VAR NAME="src"></code></pre></TMPL_IF>
<TMPL_IF NAME="expl"><TMPL_VAR NAME="expl"></TMPL_IF>