diff options
| author | Jason A. Donenfeld <Jason@zx2c4.com> | 2018-12-22 02:38:09 +0100 |
|---|---|---|
| committer | Jason A. Donenfeld <Jason@zx2c4.com> | 2026-09-18 13:52:07 +0200 |
| commit | 30559ffdb0114e3183d890b559aa6d8e149d8525 (patch) | |
| tree | 565dfe96562bcef61ead7811b2e571495ddcea69 /html.c | |
| parent | 026427aff3fba875dee4345d23e993e6b1f88220 (diff) | |
| download | cgit-30559ffdb0114e3183d890b559aa6d8e149d8525.tar.gz cgit-30559ffdb0114e3183d890b559aa6d8e149d8525.tar.bz2 cgit-30559ffdb0114e3183d890b559aa6d8e149d8525.zip | |
html: double escape literal + in URLs
It's unclear whether this is correct or whether my server is double
decoding.
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Diffstat (limited to 'html.c')
| -rw-r--r-- | html.c | 4 |
1 files changed, 2 insertions, 2 deletions
@@ -17,7 +17,7 @@ static const char* url_escape_table[256] = { "%10", "%11", "%12", "%13", "%14", "%15", "%16", "%17", "%18", "%19", "%1a", "%1b", "%1c", "%1d", "%1e", "%1f", "%20", NULL, "%22", "%23", NULL, "%25", "%26", "%27", - NULL, NULL, NULL, "%2b", NULL, NULL, NULL, NULL, + NULL, NULL, NULL, "%252b", NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, "%3c", "%3d", "%3e", "%3f", NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, @@ -200,7 +200,7 @@ void html_url_path(const char *txt) while (t && *t) { unsigned char c = *t; const char *e = url_escape_table[c]; - if (e && c != '+' && c != '&') { + if (e && c != '&') { html_raw(txt, t - txt); html(e); txt = t + 1; |
