Escape blog article
This commit is contained in:
@@ -31,10 +31,10 @@ DESC_SERVER = app.config.get('DESC_SERVER')
|
|||||||
def new_article():
|
def new_article():
|
||||||
user = '%s'% escape(session['username'])
|
user = '%s'% escape(session['username'])
|
||||||
if request.method == 'POST':
|
if request.method == 'POST':
|
||||||
title = str(request.form['title'])
|
title = escape(request.form['title'])
|
||||||
subtitle = str(request.form['subtitle'])
|
subtitle = escape(request.form['subtitle'])
|
||||||
category = str(request.form['category'])
|
category = escape(request.form['category'])
|
||||||
content = str(request.form['content'])
|
content = escape(request.form['content'])
|
||||||
status = str(request.form['status'])
|
status = str(request.form['status'])
|
||||||
post_date = time.strftime("%d/%m/%Y %H:%M:%S")
|
post_date = time.strftime("%d/%m/%Y %H:%M:%S")
|
||||||
if 'blog-unified' in request.form.keys():
|
if 'blog-unified' in request.form.keys():
|
||||||
|
|||||||
Reference in New Issue
Block a user