Enforce escaping on all template content
This commit is contained in:
		| @@ -15,7 +15,7 @@ | ||||
|       [% END %] | ||||
|       <div class="hero-unit"> | ||||
|         <h2>Change Password</h2> | ||||
|         <form class="nd_login-form" method="post" action="[% uri_for('/password') %]"> | ||||
|         <form class="nd_login-form" method="post" action="[% uri_for('/password') | none %]"> | ||||
|           <div class="form-horizontal"> | ||||
|             <input placeholder="Current Password" class="span2" name="old" type="password" required="required"/><br/> | ||||
|             <input placeholder="New Password" class="span2" name="new" type="password" required="required"/> | ||||
|   | ||||
		Reference in New Issue
	
	Block a user