Skip to content

Commit bfcd7be

Browse files
committed
Properly escape user name in error message
Thanks Demo!
1 parent 0295e1d commit bfcd7be

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

lib/junethack/sinatra_server.rb

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -274,7 +274,7 @@ def caching_check_application_start_time
274274
redirect "/login" and return
275275
else
276276
session['errors'] << "Could not register account"
277-
puts "could not register user #{params[:username]}"
277+
puts "Could not register user #{params[:username]}"
278278
redirect "/register" and return
279279
end
280280
rescue
@@ -302,7 +302,7 @@ def caching_check_application_start_time
302302

303303
haml :user, :layout => @layout
304304
else
305-
session['errors'] << "Could not find user #{params[:name]}"
305+
session['errors'] << "Could not find user #{CGI::escape(params[:name])}"
306306
end
307307
end
308308

0 commit comments

Comments
 (0)