diff options
| author | Steve Piercy <web@stevepiercy.com> | 2018-11-26 23:59:40 -0800 |
|---|---|---|
| committer | Steve Piercy <web@stevepiercy.com> | 2018-11-26 23:59:40 -0800 |
| commit | 2615104ce4ba383a46df3c27ba26cfb86654e116 (patch) | |
| tree | ad938e23efd1be67821ddfb710748e746c92c420 /docs/quick_tour/views | |
| parent | 28f24e7592fc5a7fd28874e9a350f80674583471 (diff) | |
| parent | 587fe72fae0efda3a860d37a1ea2449a41dab622 (diff) | |
| download | pyramid-2615104ce4ba383a46df3c27ba26cfb86654e116.tar.gz pyramid-2615104ce4ba383a46df3c27ba26cfb86654e116.tar.bz2 pyramid-2615104ce4ba383a46df3c27ba26cfb86654e116.zip | |
Merge remote-tracking branch 'upstream/master'
Diffstat (limited to 'docs/quick_tour/views')
| -rw-r--r-- | docs/quick_tour/views/views.py | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/docs/quick_tour/views/views.py b/docs/quick_tour/views/views.py index 95a2b60ca..ffbe1d893 100644 --- a/docs/quick_tour/views/views.py +++ b/docs/quick_tour/views/views.py @@ -1,4 +1,4 @@ -from pyramid.compat import escape +from html import escape from pyramid.httpexceptions import HTTPFound from pyramid.response import Response @@ -16,7 +16,7 @@ def home_view(request): def hello_view(request): name = request.params.get('name', 'No Name') body = '<p>Hi %s, this <a href="/goto">redirects</a></p>' - # pyramid.compat.escape to prevent Cross-Site Scripting (XSS) [CWE 79] + # Python html.escape to prevent Cross-Site Scripting (XSS) [CWE 79] return Response(body % escape(name)) |
