I checked all :value attributes in panettone.lisp and wrapped them with who:escape-string if its value comes from user-influenced places. Static values or values from panettone internals are left as is. I did not do a comprehensive check for other places where something similar could happen though. Fixes #92. Change-Id: I134acc0d2f025f173588b37c19a93589365e879b Reviewed-on: https://cl.tvl.fyi/c/depot/+/2401 Tested-by: BuildkiteCI Reviewed-by: glittershark <grfn@gws.fyi> |
||
|---|---|---|
| .. | ||
| src | ||
| test | ||
| .envrc | ||
| .gitignore | ||
| default.nix | ||
| docker-compose.yml | ||
| OWNERS | ||
| panettone.asd | ||
| shell.nix | ||