Skip to content

Commit

Permalink
escaping csv column content
Browse files Browse the repository at this point in the history
  • Loading branch information
lunny committed Jul 20, 2018
1 parent 5304fa6 commit 8da44d1
Show file tree
Hide file tree
Showing 2 changed files with 27 additions and 1 deletion.
3 changes: 2 additions & 1 deletion modules/markup/csv/csv.go
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@ package markup
import (
"bytes"
"encoding/csv"
"html"
"io"

"code.gitea.io/gitea/modules/markup"
Expand Down Expand Up @@ -46,7 +47,7 @@ func (Parser) Render(rawBytes []byte, urlPrefix string, metas map[string]string,
tmpBlock.WriteString("<tr>")
for _, field := range fields {
tmpBlock.WriteString("<td>")
tmpBlock.WriteString(field)
tmpBlock.WriteString(html.EscapeString(field))
tmpBlock.WriteString("</td>")
}
tmpBlock.WriteString("<tr>")
Expand Down
25 changes: 25 additions & 0 deletions modules/markup/csv/csv_test.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
// Copyright 2018 The Gitea Authors. All rights reserved.
// Use of this source code is governed by a MIT-style
// license that can be found in the LICENSE file.

package markup

import (
"testing"

"github.com/stretchr/testify/assert"
)

func TestRenderCSV(t *testing.T) {
var parser Parser
var kases = map[string]string{
"a": "<table class=\"table\"><tr><td>a</td><tr></table>",
"1,2": "<table class=\"table\"><tr><td>1</td><td>2</td><tr></table>",
"<br/>": "<table class=\"table\"><tr><td>&lt;br/&gt;</td><tr></table>",
}

for k, v := range kases {
res := parser.Render([]byte(k), "", nil, false)
assert.EqualValues(t, v, string(res))
}
}

0 comments on commit 8da44d1

Please sign in to comment.