* t/inline.t: accept translations of "Add a new post titled:"
(Closes: #779365)
+ [ Joey Hess ]
+ * Fix XSS in openid selector. Thanks, Raghav Bisht.
+
-- Joey Hess <id@joeyh.name> Sat, 24 Jan 2015 23:59:20 -0400
ikiwiki (3.20150107) experimental; urgency=medium
</div>
<div id="openid_input_area">
<label for="openid_identifier" class="block">Enter your OpenID:</label>
- <input id="openid_identifier" name="openid_identifier" type="text" value="<TMPL_VAR OPENID_URL>"/>
+ <input id="openid_identifier" name="openid_identifier" type="text" value="<TMPL_VAR ESCAPE=HTML OPENID_URL>"/>
<input id="openid_submit" type="submit" value="Login"/>
</div>
<TMPL_IF OPENID_ERROR>