From: Andreas Brauchli Date: Fri, 29 Jul 2016 14:49:37 +0000 (+0200) Subject: gitweb: escape link body in format_ref_marker X-Git-Url: https://git.ladys.computer/Gitweb/commitdiff_plain/fcd046648df5126917fdf5fec3b324fe8913296a5912ee6b76954fb3f3d127eb?hp=fcd046648df5126917fdf5fec3b324fe8913296a5912ee6b76954fb3f3d127eb gitweb: escape link body in format_ref_marker Fix a case where an html link can be generated from unescaped input resulting in invalid strict xhtml or potentially injected code. An overview of a repo with a tag "1.0.0&0.0.1" would previously result in an unescaped ampersand in the link body. Signed-off-by: Andreas Brauchli Acked-by: Jakub Narębski Signed-off-by: Junio C Hamano ---