Commit 4e8eba7e authored by lpsolit%gmail.com's avatar lpsolit%gmail.com

Bug 430307: Unsafe regexp used in global/userselect.html.tmpl - Patch by Jesse…

Bug 430307: Unsafe regexp used in global/userselect.html.tmpl - Patch by Jesse Clark <jjclark1982@gmail.com> r/a=LpSolit
parent 43b6f4a4
......@@ -49,10 +49,14 @@
[% custom_userlist = user.get_userlist %]
[% END %]
[% SET selected = {} %]
[% FOREACH selected_value IN value.split(', ') %]
[% SET selected.$selected_value = 1 %]
[% END %]
[% FOREACH tmpuser = custom_userlist %]
[% IF tmpuser.visible OR value.match("\\b$tmpuser.login\\b") %]
[% IF tmpuser.visible OR selected.${tmpuser.login} == 1 %]
<option value="[% tmpuser.login FILTER html %]"
[% " selected=\"selected\"" IF value.match("\\b$tmpuser.login\\b") %]
[% " selected=\"selected\"" IF selected.${tmpuser.login} == 1 %]
>[% tmpuser.identity FILTER html %]</option>
[% END %]
[% END %]
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment