Missing quoting of <>& in autogenerated forms
Bug #97976 reported by
Michael Howitz
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Zope 3 |
Fix Released
|
High
|
Unassigned |
Bug Description
In autogenerated forms <, >, & are not quoted in menus (<select>) when the source for the menu is a vocabulary. So the page isn't valid XML any more.
I put together a little example. To reproduce follow these steps:
- include the demoVendo-package in your zope (using include package in site.zcml)
- create an customer
- inside this customer create an address containing <, >, & in the name
- go to the edit-tag of the customer
- Look at the source of the html-page to see the raw characters
(Caution: Mozilla shows the characters perfectly quoted (because it shows its dom) but if you fetch the file e.g. using wget it shows up the raw characters.)
To post a comment you must log in.
Changes: submitter email, importance (medium => urgent)