Skip to content

Commit 7e6864f

Browse files
committed
escaped output values on approval page, closes mitreid-connect#1111
1 parent a316306 commit 7e6864f

File tree

1 file changed

+2
-2
lines changed
  • openid-connect-server-webapp/src/main/webapp/WEB-INF/views

1 file changed

+2
-2
lines changed

openid-connect-server-webapp/src/main/webapp/WEB-INF/views/approve.jsp

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -148,11 +148,11 @@
148148
<i class="icon-info-sign"></i> <spring:message code="approve.warning"/>:
149149
</h4>
150150
<spring:message code="approve.no_redirect_uri"/>
151-
<spring:message code="approve.redirect_uri" arguments="${redirect_uri}"/>
151+
<spring:message code="approve.redirect_uri" arguments="${ fn:escapeXml(redirect_uri) }"/>
152152
</div>
153153
</c:when>
154154
<c:otherwise>
155-
<spring:message code="approve.redirect_uri" arguments="${redirect_uri}" />
155+
<spring:message code="approve.redirect_uri" arguments="${ fn:escapeXml(redirect_uri) }" />
156156
</c:otherwise>
157157
</c:choose>
158158
</div>

0 commit comments

Comments
 (0)