Escape query string params

This commit is contained in:
Kyle Drake 2014-12-21 08:55:18 +00:00
parent 343d6b7c47
commit 128e90398e

View file

@ -113,7 +113,7 @@
if(unsavedChanges == false)
return
$.ajax({
url: '/site_files/save/<%= @filename %>?csrf_token=<%= csrf_token %>',
url: '/site_files/save/<%= Rack::Utils.escape @filename %>?csrf_token=<%= Rack::Utils.escape csrf_token %>',
data: editor.getValue(),
processData: false,
contentType: false,