From c42e604deb843d4dc8b19284e73ba5ba851b7d4f Mon Sep 17 00:00:00 2001 From: "Alexander \"Arav\" Andreev" Date: Wed, 19 Jun 2024 04:35:25 +0400 Subject: [PATCH] Whoa, don't print a raw unescaped HTML code from guests in a guestbook. --- web/guestbook.templ | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/web/guestbook.templ b/web/guestbook.templ index a302d4d..e2a918b 100644 --- a/web/guestbook.templ +++ b/web/guestbook.templ @@ -42,11 +42,9 @@ templ Guestbook(captchaID, owner string, entries []*justguestbook.Entry, pageCou for _, line := range strings.Split(entry.Message, "\n") { if len(line) > 0 && line[0] == '>' { -

@templ.Raw(line) -

+

{ line }

} else { -

@templ.Raw(line) -

+

{ line }

} } if entry.Reply != nil {