File tree 1 file changed +4
-3
lines changed
1 file changed +4
-3
lines changed Original file line number Diff line number Diff line change 2
2
* Module dependencies.
3
3
*/
4
4
5
+ var escapeHtml = require ( 'escape-html' )
5
6
var express = require ( '../../lib/express' ) ;
6
7
7
8
var verbose = process . env . NODE_ENV !== 'test'
@@ -31,7 +32,7 @@ var users = {
31
32
} ,
32
33
33
34
get : function ( req , res ) {
34
- res . send ( 'user ' + req . params . uid ) ;
35
+ res . send ( 'user ' + escapeHtml ( req . params . uid ) )
35
36
} ,
36
37
37
38
delete : function ( req , res ) {
@@ -41,11 +42,11 @@ var users = {
41
42
42
43
var pets = {
43
44
list : function ( req , res ) {
44
- res . send ( 'user ' + req . params . uid + '\'s pets' ) ;
45
+ res . send ( 'user ' + escapeHtml ( req . params . uid ) + '\'s pets' )
45
46
} ,
46
47
47
48
delete : function ( req , res ) {
48
- res . send ( 'delete ' + req . params . uid + '\'s pet ' + req . params . pid ) ;
49
+ res . send ( 'delete ' + escapeHtml ( req . params . uid ) + '\'s pet ' + escapeHtml ( req . params . pid ) )
49
50
}
50
51
} ;
51
52
You can’t perform that action at this time.
0 commit comments