Escape form for blog
This commit is contained in:
parent
7bd8614359
commit
9c36563ffd
@ -31,11 +31,11 @@ DESC_SERVER = app.config['DESC_SERVER']
|
||||
def new_article():
|
||||
user = '%s'% escape(session['username'])
|
||||
if request.method == 'POST':
|
||||
title = request.form['title']
|
||||
subtitle = request.form['subtitle']
|
||||
category = request.form['category']
|
||||
content = request.form['content']
|
||||
status = request.form['status']
|
||||
title = str(request.form['title'])
|
||||
subtitle = str(request.form['subtitle'])
|
||||
category = str(request.form['category'])
|
||||
content = str(request.form['content'])
|
||||
status = str(request.form['status'])
|
||||
post_date = time.strftime("%d/%m/%Y %H:%M:%S")
|
||||
if 'blog-unified' in request.form.keys():
|
||||
status = status+'_unified'
|
||||
@ -55,18 +55,18 @@ def edit(title):
|
||||
user='%s'% escape(session['username'])
|
||||
folder_blog = DOSSIER_PERSO + user + "/blog/articles/"
|
||||
if request.method == 'POST' :
|
||||
title = request.form['title']
|
||||
subtitle = request.form['subtitle']
|
||||
category = request.form['category']
|
||||
newcontent = request.form['content']
|
||||
newstatus = request.form['status']
|
||||
newtitle = str(request.form['title'])
|
||||
subtitle = str(request.form['subtitle'])
|
||||
category = str(request.form['category'])
|
||||
newcontent = str(request.form['content'])
|
||||
newstatus = str(request.form['status'])
|
||||
updated = time.strftime("%d/%m/%Y %H:%M:%S")
|
||||
conn = sqlite3.connect(DATABASE)
|
||||
cursor = conn.cursor()
|
||||
if 'blog-unified' in request.form.keys():
|
||||
newstatus = newstatus+'_unified'
|
||||
|
||||
cursor.execute("""UPDATE Blog_posts SET title=?, subtitle=?, category=?, last_updated=?, status=?, content=? WHERE title=? AND author=?""", (title, subtitle, category, updated, newstatus, newcontent, title, user))
|
||||
cursor.execute("""UPDATE Blog_posts SET title=?, subtitle=?, category=?, last_updated=?, status=?, content=? WHERE title=? AND author=?""", (newtitle, subtitle, category, updated, newstatus, newcontent, title, user))
|
||||
conn.commit()
|
||||
conn.close()
|
||||
return redirect(url_for('blog.list_articles_blog'))
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user