Escape form for blog

This commit is contained in:
kitoy 2025-12-22 16:23:32 +01:00
parent 7bd8614359
commit 9c36563ffd

View File

@ -31,11 +31,11 @@ DESC_SERVER = app.config['DESC_SERVER']
def new_article():
user = '%s'% escape(session['username'])
if request.method == 'POST':
title = request.form['title']
subtitle = request.form['subtitle']
category = request.form['category']
content = request.form['content']
status = request.form['status']
title = str(request.form['title'])
subtitle = str(request.form['subtitle'])
category = str(request.form['category'])
content = str(request.form['content'])
status = str(request.form['status'])
post_date = time.strftime("%d/%m/%Y %H:%M:%S")
if 'blog-unified' in request.form.keys():
status = status+'_unified'
@ -55,18 +55,18 @@ def edit(title):
user='%s'% escape(session['username'])
folder_blog = DOSSIER_PERSO + user + "/blog/articles/"
if request.method == 'POST' :
title = request.form['title']
subtitle = request.form['subtitle']
category = request.form['category']
newcontent = request.form['content']
newstatus = request.form['status']
newtitle = str(request.form['title'])
subtitle = str(request.form['subtitle'])
category = str(request.form['category'])
newcontent = str(request.form['content'])
newstatus = str(request.form['status'])
updated = time.strftime("%d/%m/%Y %H:%M:%S")
conn = sqlite3.connect(DATABASE)
cursor = conn.cursor()
if 'blog-unified' in request.form.keys():
newstatus = newstatus+'_unified'
cursor.execute("""UPDATE Blog_posts SET title=?, subtitle=?, category=?, last_updated=?, status=?, content=? WHERE title=? AND author=?""", (title, subtitle, category, updated, newstatus, newcontent, title, user))
cursor.execute("""UPDATE Blog_posts SET title=?, subtitle=?, category=?, last_updated=?, status=?, content=? WHERE title=? AND author=?""", (newtitle, subtitle, category, updated, newstatus, newcontent, title, user))
conn.commit()
conn.close()
return redirect(url_for('blog.list_articles_blog'))