Fix escaping for login page

This commit is contained in:
Omar Roth 2019-06-15 20:42:42 -05:00
parent 3be1c9261f
commit fcf377d26b
No known key found for this signature in database
GPG Key ID: B8254FB7EC3D37F2

View File

@ -32,7 +32,7 @@
<% end %>
<% if password %>
<input name="password" type="hidden" value="<%= password %>">
<input name="password" type="hidden" value="<%= HTML.escape(password) %>">
<% else %>
<label for="password"><%= translate(locale, "Password") %> :</label>
<input required class="pure-input-1" name="password" type="password" placeholder="<%= translate(locale, "Password") %>">
@ -95,7 +95,7 @@
<% end %>
<% if password %>
<input name="password" type="hidden" value="<%= password %>">
<input name="password" type="hidden" value="<%= HTML.escape(password) %>">
<% else %>
<label for="password"><%= translate(locale, "Password") %> :</label>
<input required class="pure-input-1" name="password" type="password" placeholder="<%= translate(locale, "Password") %>">