1. Thomas Waldmann
  2. moin-1.9

Commits

Thomas Waldmann  committed d0567fb Draft

escape user- or admin-defined css url

  • Participants
  • Parent commits d3090fb
  • Branches default

Comments (0)

Files changed (1)

File MoinMoin/theme/__init__.py

View file
         if theme:
             href = '%s/%s/css/%s.css' % (self.cfg.url_prefix_static, self.name, href)
         attrs = 'type="text/css" charset="%s" media="%s" href="%s"' % (
-                self.stylesheetsCharset, media, href, )
+                self.stylesheetsCharset, media, wikiutil.escape(href, True), )
         if title:
             return '<link rel="alternate stylesheet" %s title="%s">' % (attrs, title)
         else: