# HG changeset patch # User Matt Mackall # Date 1381184477 25200 # Node ID 5cbf413ce658d176afbdd7109f499affd6ba2ea6 # Parent 21de61bc2ab59ec6bb1416ed9441b638db6d2c8c hgweb: escape branch names in graph view diff -r 21de61bc2ab5 -r 5cbf413ce658 mercurial/hgweb/webcommands.py --- a/mercurial/hgweb/webcommands.py Wed Oct 02 11:16:03 2013 +0200 +++ b/mercurial/hgweb/webcommands.py Mon Oct 07 15:21:17 2013 -0700 @@ -913,7 +913,7 @@ desc = templatefilters.firstline(ctx.description()) desc = cgi.escape(templatefilters.nonempty(desc)) user = cgi.escape(templatefilters.person(ctx.user())) - branch = ctx.branch() + branch = cgi.escape(ctx.branch()) try: branchnode = web.repo.branchtip(branch) except error.RepoLookupError: