Skip to content

Commit 66d56a2

Browse files
Bugfix: Escaped HTML in messages and errors (#1890)
* assume flashed messages and errors are safe
1 parent 62f8239 commit 66d56a2

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

src/cryptoadvance/specter/templates/base.jinja

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -91,12 +91,12 @@
9191
{% with messages = get_flashed_messages(with_categories=True) %}
9292
{% if messages %}
9393
{% for category, message in messages | unique %}
94-
<message-box type="{{ category }}">{{ message }}</message-box>
94+
<message-box type="{{ category }}">{{ message | safe }}</message-box>
9595
{% endfor %}
9696
{% endif %}
9797
{% endwith %}
9898
{% if error %}
99-
<message-box type="error">{{ _("ERROR:") }} {{error}}</message-box>
99+
<message-box type="error">{{ _("ERROR:") }} {{error | safe }}</message-box>
100100
{% endif %}
101101
</div>
102102

0 commit comments

Comments
 (0)