special chars not escaped in site.zcml

Bug #155193 reported by Yoshinori K. Okuji
2
Affects Status Importance Assigned to Milestone
zopeproject
Confirmed
Undecided
Unassigned

Bug Description

When generating a project with zopeproject, if one enters special characters, such as &, for a user or a password, the string is embedded into site.zcml as it is. Thus a XML validation failure occurs when starting up a server.

A fix could be to use xml.sax.saxutils.quoteattr explicitly.

This is reproducible with zopeproject 0.4.1.

Cheers,
Okuji

Changed in zopeproject:
status: New → Confirmed
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.