File tree Expand file tree Collapse file tree 1 file changed +4
-3
lines changed
Expand file tree Collapse file tree 1 file changed +4
-3
lines changed Original file line number Diff line number Diff line change 22 * Module dependencies.
33 */
44
5+ var escapeHtml = require ( 'escape-html' )
56var express = require ( '../../lib/express' ) ;
67
78var verbose = process . env . NODE_ENV !== 'test'
@@ -31,7 +32,7 @@ var users = {
3132 } ,
3233
3334 get : function ( req , res ) {
34- res . send ( 'user ' + req . params . uid ) ;
35+ res . send ( 'user ' + escapeHtml ( req . params . uid ) )
3536 } ,
3637
3738 delete : function ( req , res ) {
@@ -41,11 +42,11 @@ var users = {
4142
4243var pets = {
4344 list : function ( req , res ) {
44- res . send ( 'user ' + req . params . uid + '\'s pets' ) ;
45+ res . send ( 'user ' + escapeHtml ( req . params . uid ) + '\'s pets' )
4546 } ,
4647
4748 delete : function ( req , res ) {
48- res . send ( 'delete ' + req . params . uid + '\'s pet ' + req . params . pid ) ;
49+ res . send ( 'delete ' + escapeHtml ( req . params . uid ) + '\'s pet ' + escapeHtml ( req . params . pid ) )
4950 }
5051} ;
5152
You can’t perform that action at this time.
0 commit comments