Gerrit Patch Uploader has uploaded a new change for review.

  https://gerrit.wikimedia.org/r/248615

Change subject: EntityTermsView.php: Escape href parameter
......................................................................

EntityTermsView.php: Escape href parameter

Bug: T116472
Change-Id: I9311a7be67cc559e5dcc68f0369f31260a7039c3
---
M view/src/EntityTermsView.php
1 file changed, 3 insertions(+), 2 deletions(-)


  git pull ssh://gerrit.wikimedia.org:29418/mediawiki/extensions/Wikibase 
refs/changes/15/248615/1

diff --git a/view/src/EntityTermsView.php b/view/src/EntityTermsView.php
index 9bf16f6..6bb7e6b 100644
--- a/view/src/EntityTermsView.php
+++ b/view/src/EntityTermsView.php
@@ -218,9 +218,10 @@
                        'td',
                        $languageCode,
                        $this->templateFactory->render( 
'wikibase-entitytermsforlanguageview-language',
-                               $title === null
+                               htmlspecialchars( $title === null
                                        ? '#'
-                                       : $title->getLocalURL( array( 'setlang' 
=> $languageCode ) ),
+                                       : $title->getLocalURL( array( 'setlang' 
=> $languageCode ) )
+                               ),
                                htmlspecialchars( 
$this->languageNameLookup->getName( $languageCode, $this->languageCode ) )
                        ),
                        $this->templateFactory->render( 'wikibase-labelview',

-- 
To view, visit https://gerrit.wikimedia.org/r/248615
To unsubscribe, visit https://gerrit.wikimedia.org/r/settings

Gerrit-MessageType: newchange
Gerrit-Change-Id: I9311a7be67cc559e5dcc68f0369f31260a7039c3
Gerrit-PatchSet: 1
Gerrit-Project: mediawiki/extensions/Wikibase
Gerrit-Branch: master
Gerrit-Owner: Gerrit Patch Uploader <[email protected]>

_______________________________________________
MediaWiki-commits mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/mediawiki-commits

Reply via email to