Repository: wicket
Updated Branches:
  refs/heads/master 726c1400e -> 3b9e1169d


Escape the value of the hidden field holding the focused element id

(cherry picked from commit 149cc36f30bcd3b31b727941f701e12ecbe3440f)
(cherry picked from commit 849e0430730846048a512ea56689432ea0f2e067)


Project: http://git-wip-us.apache.org/repos/asf/wicket/repo
Commit: http://git-wip-us.apache.org/repos/asf/wicket/commit/3b9e1169
Tree: http://git-wip-us.apache.org/repos/asf/wicket/tree/3b9e1169
Diff: http://git-wip-us.apache.org/repos/asf/wicket/diff/3b9e1169

Branch: refs/heads/master
Commit: 3b9e1169d5deaf73e734a880214d6e5d2d735197
Parents: 726c140
Author: Martin Tzvetanov Grigorov <[email protected]>
Authored: Wed Sep 3 17:34:56 2014 +0300
Committer: Martin Tzvetanov Grigorov <[email protected]>
Committed: Wed Sep 3 17:39:53 2014 +0300

----------------------------------------------------------------------
 .../markup/html/repeater/data/table/filter/FilterForm.java         | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
----------------------------------------------------------------------


http://git-wip-us.apache.org/repos/asf/wicket/blob/3b9e1169/wicket-extensions/src/main/java/org/apache/wicket/extensions/markup/html/repeater/data/table/filter/FilterForm.java
----------------------------------------------------------------------
diff --git 
a/wicket-extensions/src/main/java/org/apache/wicket/extensions/markup/html/repeater/data/table/filter/FilterForm.java
 
b/wicket-extensions/src/main/java/org/apache/wicket/extensions/markup/html/repeater/data/table/filter/FilterForm.java
index ea355fd..97007e2 100644
--- 
a/wicket-extensions/src/main/java/org/apache/wicket/extensions/markup/html/repeater/data/table/filter/FilterForm.java
+++ 
b/wicket-extensions/src/main/java/org/apache/wicket/extensions/markup/html/repeater/data/table/filter/FilterForm.java
@@ -90,7 +90,7 @@ public class FilterForm<T> extends Form<T>
                getResponse().write(
                        String.format(
                                "<div style='position: absolute; left: -9999px; 
width: 1px; height: 1px;'><input type='hidden' name='%s' id='%s' 
value='%s'/><input type='submit'/></div>",
-                               id, id, value));
+                               id, id, Strings.escapeMarkup(value)));
        }
 
        /**

Reply via email to