Enforce escaping on all template content

This commit is contained in:
Oliver Gorwits
2019-09-23 14:22:00 +01:00
parent 5f378a39ea
commit deb9b62c7f
77 changed files with 392 additions and 387 deletions

View File

@@ -15,7 +15,7 @@
[% END %]
<div class="hero-unit">
<h2>Change Password</h2>
<form class="nd_login-form" method="post" action="[% uri_for('/password') %]">
<form class="nd_login-form" method="post" action="[% uri_for('/password') | none %]">
<div class="form-horizontal">
<input placeholder="Current Password" class="span2" name="old" type="password" required="required"/><br/>
<input placeholder="New Password" class="span2" name="new" type="password" required="required"/>