Author: simoneg
Date: Thu Feb  4 15:23:06 2010
New Revision: 906522

URL: http://svn.apache.org/viewvc?rev=906522&view=rev
Log:
Escape for HTML special chars

Modified:
    
labs/magma/trunk/website-beansview/src/main/java/org/apache/magma/website/htmlpieces/TextFieldHtmlFormPiece.java

Modified: 
labs/magma/trunk/website-beansview/src/main/java/org/apache/magma/website/htmlpieces/TextFieldHtmlFormPiece.java
URL: 
http://svn.apache.org/viewvc/labs/magma/trunk/website-beansview/src/main/java/org/apache/magma/website/htmlpieces/TextFieldHtmlFormPiece.java?rev=906522&r1=906521&r2=906522&view=diff
==============================================================================
--- 
labs/magma/trunk/website-beansview/src/main/java/org/apache/magma/website/htmlpieces/TextFieldHtmlFormPiece.java
 (original)
+++ 
labs/magma/trunk/website-beansview/src/main/java/org/apache/magma/website/htmlpieces/TextFieldHtmlFormPiece.java
 Thu Feb  4 15:23:06 2010
@@ -2,6 +2,7 @@
 
 import java.util.Map;
 
+import org.apache.commons.lang.StringEscapeUtils;
 import org.apache.magma.beans.MagmaBeanSupport;
 import org.apache.magma.beans.PropertyInfo;
 import org.apache.magma.i18n.Formatter;
@@ -103,12 +104,15 @@
                }
                out.append(" value=\"");
                PropertyInfo property = this.getProperty();
+               String val = null;
                if (property != null) {
-                       out.append(property.toUser(value));
+                       val = property.toUser(value);
                } else {
                        Formatter formatter = 
Formatters.getFormatterFor(this.handledClass);
-                       out.append(formatter.to(value));                        
+                       val = formatter.to(value);                      
                }
+               val = StringEscapeUtils.escapeHtml(val);
+               out.append(val);
                out.append("\"/>");             
                return out.toString();
        }



---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to