summaryrefslogtreecommitdiff
path: root/docs/quick_tour/views
diff options
context:
space:
mode:
authorSteve Piercy <web@stevepiercy.com>2018-11-26 23:59:40 -0800
committerSteve Piercy <web@stevepiercy.com>2018-11-26 23:59:40 -0800
commit2615104ce4ba383a46df3c27ba26cfb86654e116 (patch)
treead938e23efd1be67821ddfb710748e746c92c420 /docs/quick_tour/views
parent28f24e7592fc5a7fd28874e9a350f80674583471 (diff)
parent587fe72fae0efda3a860d37a1ea2449a41dab622 (diff)
downloadpyramid-2615104ce4ba383a46df3c27ba26cfb86654e116.tar.gz
pyramid-2615104ce4ba383a46df3c27ba26cfb86654e116.tar.bz2
pyramid-2615104ce4ba383a46df3c27ba26cfb86654e116.zip
Merge remote-tracking branch 'upstream/master'
Diffstat (limited to 'docs/quick_tour/views')
-rw-r--r--docs/quick_tour/views/views.py4
1 files changed, 2 insertions, 2 deletions
diff --git a/docs/quick_tour/views/views.py b/docs/quick_tour/views/views.py
index 95a2b60ca..ffbe1d893 100644
--- a/docs/quick_tour/views/views.py
+++ b/docs/quick_tour/views/views.py
@@ -1,4 +1,4 @@
-from pyramid.compat import escape
+from html import escape
from pyramid.httpexceptions import HTTPFound
from pyramid.response import Response
@@ -16,7 +16,7 @@ def home_view(request):
def hello_view(request):
name = request.params.get('name', 'No Name')
body = '<p>Hi %s, this <a href="/goto">redirects</a></p>'
- # pyramid.compat.escape to prevent Cross-Site Scripting (XSS) [CWE 79]
+ # Python html.escape to prevent Cross-Site Scripting (XSS) [CWE 79]
return Response(body % escape(name))