Skip to content

Commit f1c54e3

Browse files
authored
escape row and bulk actions form value in template (#615)
1 parent bd59d51 commit f1c54e3

File tree

3 files changed

+3
-3
lines changed

3 files changed

+3
-3
lines changed

starlette_admin/__init__.py

+1-1
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
__version__ = "0.15.0rc3"
1+
__version__ = "0.15.0rc4"
22

33
from ._types import ExportType as ExportType
44
from ._types import RequestAction as RequestAction

starlette_admin/templates/actions.html

+1-1
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@
2424
data-name="{{ action.name }}"
2525
data-submit-btn-text="{{ action.submit_btn_text }}"
2626
data-submit-btn-class="{{ action.submit_btn_class }}"
27-
data-form="{{ action.form }}"
27+
data-form="{{ action.form |forceescape }}"
2828
>
2929
{% if action.icon_class %}
3030
<i class="{{ action.icon_class }} me-2"></i>

starlette_admin/templates/row-actions.html

+1-1
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@
1515
{% endif %}
1616
data-submit-btn-text="{{ action.submit_btn_text }}"
1717
data-submit-btn-class="{{ action.submit_btn_class }}"
18-
data-form="{{ action.form }}"
18+
data-form="{{ action.form |forceescape }}"
1919
{% endif %}
2020
data-is-row-action="true"
2121
data-name="{{ action.name }}"

0 commit comments

Comments
 (0)