diff gnv/src/main/java/de/intevation/gnv/action/WMSAction.java @ 705:f550bd27a3f1

Html characters in strings inserted by the user are quoted (issue221). gnv/trunk@969 c6561f87-3c4e-4783-a992-168aeb5c3f6f
author Ingo Weinzierl <ingo.weinzierl@intevation.de>
date Thu, 22 Apr 2010 12:58:44 +0000
parents 254f062e334b
children d91ffd0e8239
line wrap: on
line diff
--- a/gnv/src/main/java/de/intevation/gnv/action/WMSAction.java	Mon Apr 19 15:36:11 2010 +0000
+++ b/gnv/src/main/java/de/intevation/gnv/action/WMSAction.java	Thu Apr 22 12:58:44 2010 +0000
@@ -94,12 +94,12 @@
                         String[] values   = request.getParameterValues(name);
                         String value      = request.getParameter(name);
                         InputParameter ip = new DefaultInputParameter(name,
-                                values);
+                                encode(values));
                         ips.add(ip);
 
                         if (value != null) {
                             ++params;
-                            diagrammOptions.setValue(name, value);
+                            diagrammOptions.setValue(name, encode(value));
                         }
                     }
 
@@ -178,6 +178,5 @@
             return super.getExceptionForward(mapping);
         }
     }
-
 }
 // vim:set ts=4 sw=4 si et sta sts=4 fenc=utf-8 :

http://dive4elements.wald.intevation.org