Commit e41554b2 by Chris Dodge

be sure to encode the display strings

parent ebbeeb16
import logging
import re
import cgi
from django.conf import settings
from django.contrib.sites.models import Site
......@@ -95,7 +96,7 @@ def course_wiki_redirect(request, course_id):
root,
course_slug,
title=course_slug,
content="This is the wiki for **{0}**'s _{1}_.".format(course.display_org_with_default, course.display_name_with_default),
content=cgi.escape("This is the wiki for **{0}**'s _{1}_.".format(course.display_org_with_default, course.display_name_with_default)),
user_message="Course page automatically created.",
user=None,
ip_address=None,
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment