From: David Bremner Date: Mon, 5 Sep 2022 11:03:39 +0000 (-0300) Subject: nmweb: escape subject in search view X-Git-Tag: 0.38_rc0~70 X-Git-Url: https://git.cworth.org/git?p=notmuch;a=commitdiff_plain;h=48d6b31485dfd3110b82fd8829063297284c78c0 nmweb: escape subject in search view Fix a bug reported by Jakub Wilk [1]. [1]: id:20220822064717.qftn4tr7cs4r2ian@jwilk.net --- diff --git a/devel/notmuch-web/nmweb.py b/devel/notmuch-web/nmweb.py index 928e4863..7b555c62 100755 --- a/devel/notmuch-web/nmweb.py +++ b/devel/notmuch-web/nmweb.py @@ -131,7 +131,7 @@ env.globals['mailto_addrs'] = mailto_addrs def link_msg(msg): lnk = quote_plus(msg.messageid.encode('utf8')) try: - subj = msg.header('Subject') + subj = html.escape(msg.header('Subject')) except LookupError: subj = "" out = '%s' % (prefix, lnk, subj)