From b76107bb240c54ba4d4c8e1d2badd412e5c473fa Mon Sep 17 00:00:00 2001
From: James Moger <james.moger@gitblit.com>
Date: Tue, 04 Nov 2014 17:23:50 -0500
Subject: [PATCH] Whitelist the "target" link attribute in the XSS filter
---
src/main/java/com/gitblit/utils/ModelUtils.java | 2 +-
1 files changed, 1 insertions(+), 1 deletions(-)
diff --git a/src/main/java/com/gitblit/utils/ModelUtils.java b/src/main/java/com/gitblit/utils/ModelUtils.java
index d053db6..6fb4c0a 100644
--- a/src/main/java/com/gitblit/utils/ModelUtils.java
+++ b/src/main/java/com/gitblit/utils/ModelUtils.java
@@ -38,7 +38,7 @@
userRepoPrefix = Constants.DEFAULT_USER_REPOSITORY_PREFIX;
return;
}
-
+
String newPrefix = prefix.replace('\\', '/');
if (prefix.charAt(0) == '/') {
newPrefix = prefix.substring(1);
--
Gitblit v1.9.1