mirror of
				https://github.com/django/django.git
				synced 2025-10-29 00:26:07 +00:00 
			
		
		
		
	Fixed #2761 -- Apply escaping to values in form checkbox attributes.
git-svn-id: http://code.djangoproject.com/svn/django/trunk@3775 bcc190cf-cafb-0310-a4f2-bffc1f526a37
This commit is contained in:
		| @@ -639,8 +639,8 @@ class CheckboxSelectMultipleField(SelectMultipleField): | ||||
|                 checked_html = ' checked="checked"' | ||||
|             field_name = '%s%s' % (self.field_name, value) | ||||
|             output.append('<li><input type="checkbox" id="%s" class="v%s" name="%s"%s /> <label for="%s">%s</label></li>' % \ | ||||
|                 (self.get_id() + value , self.__class__.__name__, field_name, checked_html, | ||||
|                 self.get_id() + value, choice)) | ||||
|                 (self.get_id() + escape(value), self.__class__.__name__, field_name, checked_html, | ||||
|                 self.get_id() + escape(value), choice)) | ||||
|         output.append('</ul>') | ||||
|         return '\n'.join(output) | ||||
|  | ||||
|   | ||||
		Reference in New Issue
	
	Block a user