Browse Source

Fixes #13401: Fixed lack of escaping of request dump at exception screens

tags/2.0.11
Alexander Makarov 8 years ago committed by GitHub
parent
commit
97171a0db7
  1. 2
      framework/CHANGELOG.md
  2. 2
      framework/web/ErrorHandler.php

2
framework/CHANGELOG.md

@ -104,7 +104,7 @@ Yii Framework 2 Change Log
- Enh: Added support for field `yii\console\controllers\BaseMigrateController::$migrationNamespaces` setup from CLI (schmunk42)
- Bug #13287: Fixed translating "and" separator in `UniqueValidator` error message (jetexe)
- Enh #11464: Populate foreign key names from schema (joaoppereira)
- Bug #13401: Fixed lack of escaping of request dump at exception screens (samdark)
2.0.10 October 20, 2016
-----------------------

2
framework/web/ErrorHandler.php

@ -323,7 +323,7 @@ class ErrorHandler extends \yii\base\ErrorHandler
}
}
return '<pre>' . rtrim($request, "\n") . '</pre>';
return '<pre>' . $this->htmlEncode(rtrim($request, "\n")) . '</pre>';
}
/**

Loading…
Cancel
Save