From 31d764cadfa52e851db9eccb0e84b567ff4c0579 Mon Sep 17 00:00:00 2001 From: Malcolm Tredinnick Date: Thu, 21 Sep 2006 13:35:34 +0000 Subject: [PATCH] Fixed #2761 -- Apply escaping to values in form checkbox attributes. git-svn-id: http://code.djangoproject.com/svn/django/trunk@3775 bcc190cf-cafb-0310-a4f2-bffc1f526a37 --- django/forms/__init__.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/django/forms/__init__.py b/django/forms/__init__.py index 730f7a54da..241795312e 100644 --- a/django/forms/__init__.py +++ b/django/forms/__init__.py @@ -639,8 +639,8 @@ class CheckboxSelectMultipleField(SelectMultipleField): checked_html = ' checked="checked"' field_name = '%s%s' % (self.field_name, value) output.append('
  • ' % \ - (self.get_id() + value , self.__class__.__name__, field_name, checked_html, - self.get_id() + value, choice)) + (self.get_id() + escape(value), self.__class__.__name__, field_name, checked_html, + self.get_id() + escape(value), choice)) output.append('') return '\n'.join(output)