fixed issue 1808:HTML Injection on Terminal(shell) online
This commit is contained in:
@@ -1 +1 @@
|
|||||||
Version 2.8.2-stable+timestamp.2013.12.07.10.19.34
|
Version 2.8.2-stable+timestamp.2013.12.07.18.35.39
|
||||||
|
|||||||
@@ -3,6 +3,7 @@ import cStringIO
|
|||||||
import gluon.contrib.shell
|
import gluon.contrib.shell
|
||||||
import code
|
import code
|
||||||
import thread
|
import thread
|
||||||
|
import cgi
|
||||||
from gluon.shell import env
|
from gluon.shell import env
|
||||||
|
|
||||||
if DEMO_MODE or MULTI_USER_MODE:
|
if DEMO_MODE or MULTI_USER_MODE:
|
||||||
@@ -40,7 +41,7 @@ def callback():
|
|||||||
k = len(session['commands:' + app]) - 1
|
k = len(session['commands:' + app]) - 1
|
||||||
#output = PRE(output)
|
#output = PRE(output)
|
||||||
#return TABLE(TR('In[%i]:'%k,PRE(command)),TR('Out[%i]:'%k,output))
|
#return TABLE(TR('In[%i]:'%k,PRE(command)),TR('Out[%i]:'%k,output))
|
||||||
return 'In [%i] : %s%s\n' % (k + 1, command, output)
|
return cgi.escape('In [%i] : %s%s\n' % (k + 1, command, output))
|
||||||
|
|
||||||
|
|
||||||
def reset():
|
def reset():
|
||||||
|
|||||||
@@ -2,40 +2,41 @@
|
|||||||
{{block sectionclass}}shell{{end}}
|
{{block sectionclass}}shell{{end}}
|
||||||
<!-- begin "shell" block -->
|
<!-- begin "shell" block -->
|
||||||
<div id="wrapper">
|
<div id="wrapper">
|
||||||
<div class="row-fluid">
|
<div class="row-fluid">
|
||||||
<div class="output-wrapper span8">
|
<div class="output-wrapper span8">
|
||||||
<textarea id="output" readonly="readonly">web2py Shell {{=request.env.web2py_version}}</textarea>
|
<textarea id="output" readonly="readonly">web2py Shell {{=request.env.web2py_version}}
|
||||||
</div>
|
</textarea>
|
||||||
</div>
|
</div>
|
||||||
|
</div>
|
||||||
<div class="row-fluid">
|
|
||||||
<form id="form" action="{{=URL(r=request,f='callback',args=app)}}" method="get" class="span8">
|
<div class="row-fluid">
|
||||||
<div id="shellwrapper">
|
<form id="form" action="{{=URL(r=request,f='callback',args=app)}}" method="get" class="span8">
|
||||||
<div class="prompt-wrapper">
|
<div id="shellwrapper">
|
||||||
<div class="prompt-container">
|
<div class="prompt-wrapper">
|
||||||
<textarea class="prompt" name="statement" id="statement"></textarea>
|
<div class="prompt-container">
|
||||||
</div>
|
<textarea class="prompt" name="statement" id="statement"></textarea>
|
||||||
<a href="#" rel="tooltip" data-placement="right" data-original-title="{{=T('Type some Python code in here and hit Return (Enter) to execute it.')}}">
|
</div>
|
||||||
{{=helpicon()}}
|
<a href="#" rel="tooltip" data-placement="right" data-original-title="{{=T('Type some Python code in here and hit Return (Enter) to execute it.')}}">
|
||||||
<span>Type some Python code in here and hit Return (Enter) to execute it.</span>
|
{{=helpicon()}}
|
||||||
</a>
|
<span>Type some Python code in here and hit Return (Enter) to execute it.</span>
|
||||||
</div>
|
</a>
|
||||||
<div id="caret"><span>>>></span></div>
|
|
||||||
<div id="autoscroll">autoscroll</div>
|
|
||||||
</div>
|
|
||||||
</form>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
<div class="row-fluid clearfix">
|
|
||||||
<div class="help alert alert-info span6">
|
|
||||||
<ul>
|
|
||||||
<li>Using the shell may lock the database to other users of this app.</li>
|
|
||||||
<li>Each db statement is automatically committed.</li>
|
|
||||||
<li>Creating new tables dynamically is not allowed.</li>
|
|
||||||
<li>Models are automatically imported in the shell.</li>
|
|
||||||
</ul>
|
|
||||||
</div>
|
|
||||||
</div>
|
</div>
|
||||||
|
<div id="caret"><span>>>></span></div>
|
||||||
|
<div id="autoscroll">autoscroll</div>
|
||||||
|
</div>
|
||||||
|
</form>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="row-fluid clearfix">
|
||||||
|
<div class="help alert alert-info span6">
|
||||||
|
<ul>
|
||||||
|
<li>Using the shell may lock the database to other users of this app.</li>
|
||||||
|
<li>Each db statement is automatically committed.</li>
|
||||||
|
<li>Creating new tables dynamically is not allowed.</li>
|
||||||
|
<li>Models are automatically imported in the shell.</li>
|
||||||
|
</ul>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
</div>
|
</div>
|
||||||
<script type="text/javascript" src="{{=URL('static', 'js/autoscroll.js')}}"></script>
|
<script type="text/javascript" src="{{=URL('static', 'js/autoscroll.js')}}"></script>
|
||||||
|
|
||||||
@@ -113,4 +114,4 @@ jQuery(document).ready(function(){
|
|||||||
});
|
});
|
||||||
});
|
});
|
||||||
</script>
|
</script>
|
||||||
<!-- end "shell" block -->
|
<!-- end "shell" block -->
|
||||||
|
|||||||
Reference in New Issue
Block a user