From 8125b8ceae58d23a549ec7f318bed6d9ca946c45 Mon Sep 17 00:00:00 2001 From: Kurt Garloff Date: Thu, 7 Dec 2023 11:05:37 +0100 Subject: [PATCH] Use html.escape for all output that may be user-influenced. (#404) This is cleaner than filtering the input. Suggested by @joshmue. Signed-off-by: Kurt Garloff --- Tests/iaas/flavor-naming/flavor-form.py | 13 +++++-------- 1 file changed, 5 insertions(+), 8 deletions(-) diff --git a/Tests/iaas/flavor-naming/flavor-form.py b/Tests/iaas/flavor-naming/flavor-form.py index e238fbbb9..7b8324113 100755 --- a/Tests/iaas/flavor-naming/flavor-form.py +++ b/Tests/iaas/flavor-naming/flavor-form.py @@ -16,6 +16,7 @@ import sys import re import urllib.parse +import html import importlib fnmck = importlib.import_module("flavor-name-check") @@ -28,10 +29,6 @@ def parse_name(fnm): "return tuple with flavor description" global FLAVOR_SPEC, FLAVOR_NAME, ERROR - # Sanitize - # fnm = re.sub(r"<( *script)", r"