From 135f41041dfe69b35f3fbaadf152918397a5b6ed Mon Sep 17 00:00:00 2001 From: LAdm Date: Thu, 10 Aug 2017 06:49:36 +0200 Subject: [PATCH] fixes #1724 call func instead of module in url_is_acceptable --- gluon/sanitizer.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/gluon/sanitizer.py b/gluon/sanitizer.py index 5cd2ea4a..b98b7477 100644 --- a/gluon/sanitizer.py +++ b/gluon/sanitizer.py @@ -145,7 +145,7 @@ class XssCleaner(HTMLParser): if url.startswith('#'): return True else: - parsed = urlparse(url) + parsed = urlparse.urlparse(url) return ((parsed[0] in self.allowed_schemes and '.' in parsed[1]) or (parsed[0] in self.allowed_schemes and '@' in parsed[2]) or (parsed[0] == '' and parsed[2].startswith('/')))