From 8baa4e813ef9d3daf8ebe7fadf7c56a4d80ebc14 Mon Sep 17 00:00:00 2001 From: Colin Davis Date: Tue, 30 Aug 2011 23:04:30 -0400 Subject: [PATCH] saftey --- webfront.py | 1 + 1 file changed, 1 insertion(+) diff --git a/webfront.py b/webfront.py index 43767dd..0f22786 100755 --- a/webfront.py +++ b/webfront.py @@ -275,6 +275,7 @@ class ImgHandler(tornado.web.RequestHandler): gravatar_url = "http://www.gravatar.com/avatar.php?" gravatar_url += urllib.urlencode({'gravatar_id':hashlib.md5(string.lower()).hexdigest(), 'default':default, 'size':str(sizey)}) if tornado.escape.xhtml_escape(self.get_argument("gravatar")) == 'hashed': + string = urllib.quote(string) default = "404" # construct the url gravatar_url = "http://www.gravatar.com/avatar.php?"