Repository: wicket Updated Branches: refs/heads/master 726c1400e -> 3b9e1169d
Escape the value of the hidden field holding the focused element id (cherry picked from commit 149cc36f30bcd3b31b727941f701e12ecbe3440f) (cherry picked from commit 849e0430730846048a512ea56689432ea0f2e067) Project: http://git-wip-us.apache.org/repos/asf/wicket/repo Commit: http://git-wip-us.apache.org/repos/asf/wicket/commit/3b9e1169 Tree: http://git-wip-us.apache.org/repos/asf/wicket/tree/3b9e1169 Diff: http://git-wip-us.apache.org/repos/asf/wicket/diff/3b9e1169 Branch: refs/heads/master Commit: 3b9e1169d5deaf73e734a880214d6e5d2d735197 Parents: 726c140 Author: Martin Tzvetanov Grigorov <[email protected]> Authored: Wed Sep 3 17:34:56 2014 +0300 Committer: Martin Tzvetanov Grigorov <[email protected]> Committed: Wed Sep 3 17:39:53 2014 +0300 ---------------------------------------------------------------------- .../markup/html/repeater/data/table/filter/FilterForm.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) ---------------------------------------------------------------------- http://git-wip-us.apache.org/repos/asf/wicket/blob/3b9e1169/wicket-extensions/src/main/java/org/apache/wicket/extensions/markup/html/repeater/data/table/filter/FilterForm.java ---------------------------------------------------------------------- diff --git a/wicket-extensions/src/main/java/org/apache/wicket/extensions/markup/html/repeater/data/table/filter/FilterForm.java b/wicket-extensions/src/main/java/org/apache/wicket/extensions/markup/html/repeater/data/table/filter/FilterForm.java index ea355fd..97007e2 100644 --- a/wicket-extensions/src/main/java/org/apache/wicket/extensions/markup/html/repeater/data/table/filter/FilterForm.java +++ b/wicket-extensions/src/main/java/org/apache/wicket/extensions/markup/html/repeater/data/table/filter/FilterForm.java @@ -90,7 +90,7 @@ public class FilterForm<T> extends Form<T> getResponse().write( String.format( "<div style='position: absolute; left: -9999px; width: 1px; height: 1px;'><input type='hidden' name='%s' id='%s' value='%s'/><input type='submit'/></div>", - id, id, value)); + id, id, Strings.escapeMarkup(value))); } /**
