diff --git a/README.md b/README.md index 3c92baaf..05a5521c 100644 --- a/README.md +++ b/README.md @@ -51,7 +51,7 @@ The official docker images are available on [Dockerhub](https://hub.docker.com/r ### CLI ``` - Mango - Manga Server and Web Reader. Version 0.26.0 + Mango - Manga Server and Web Reader. Version 0.26.1 Usage: diff --git a/shard.lock b/shard.lock index 292a16fc..9d0756e7 100644 --- a/shard.lock +++ b/shard.lock @@ -68,6 +68,10 @@ shards: git: https://github.com/luislavena/radix.git version: 0.4.1 + sanitize: + git: https://github.com/hkalexling/sanitize.git + version: 0.1.0+git.commit.e09520e972d0d9b70b71bb003e6831f7c2c59dce + sqlite3: git: https://github.com/crystal-lang/crystal-sqlite3.git version: 0.18.0 diff --git a/shard.yml b/shard.yml index 14a49aa5..43ffd39c 100644 --- a/shard.yml +++ b/shard.yml @@ -1,5 +1,5 @@ name: mango -version: 0.26.0 +version: 0.26.1 authors: - Alex Ling @@ -42,3 +42,5 @@ dependencies: branch: master mg: github: hkalexling/mg + sanitize: + github: hkalexling/sanitize diff --git a/src/mango.cr b/src/mango.cr index e57750d4..0eb42133 100644 --- a/src/mango.cr +++ b/src/mango.cr @@ -7,7 +7,7 @@ require "option_parser" require "clim" require "tallboy" -MANGO_VERSION = "0.26.0" +MANGO_VERSION = "0.26.1" # From http://www.network-science.de/ascii/ BANNER = %{ diff --git a/src/routes/admin.cr b/src/routes/admin.cr index c3692c99..23481f96 100644 --- a/src/routes/admin.cr +++ b/src/routes/admin.cr @@ -1,3 +1,5 @@ +require "sanitize" + struct AdminRouter def initialize get "/admin" do |env| @@ -14,13 +16,13 @@ struct AdminRouter end get "/admin/user/edit" do |env| - username = env.params.query["username"]? + sanitizer = Sanitize::Policy::Text.new + username = env.params.query["username"]?.try { |s| sanitizer.process s } admin = env.params.query["admin"]? if admin admin = admin == "true" end - error = env.params.query["error"]? - current_user = get_username env + error = env.params.query["error"]?.try { |s| sanitizer.process s } new_user = username.nil? && admin.nil? layout "user-edit" end