From 39f125ca3b0dcd3e1d7318de2e193e4335a4b9a1 Mon Sep 17 00:00:00 2001 From: Byron Jones Date: Thu, 21 Mar 2013 13:09:12 +0800 Subject: Bug 853314: unable to edit bugzilla push options - insecure dependency --- extensions/Push/lib/Admin.pm | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) (limited to 'extensions/Push/lib/Admin.pm') diff --git a/extensions/Push/lib/Admin.pm b/extensions/Push/lib/Admin.pm index d7df25c09..f579409bd 100644 --- a/extensions/Push/lib/Admin.pm +++ b/extensions/Push/lib/Admin.pm @@ -13,7 +13,7 @@ use warnings; use Bugzilla; use Bugzilla::Error; use Bugzilla::Extension::Push::Util; -use Bugzilla::Util qw(trim detaint_natural); +use Bugzilla::Util qw(trim detaint_natural trick_taint); use base qw(Exporter); our @EXPORT = qw( @@ -67,6 +67,7 @@ sub _update_config_from_form { # update foreach my $option ($config->options) { my $option_name = $option->{name}; + trick_taint($values->{$option_name}); $config->{$option_name} = $values->{$option_name}; } $config->update(); -- cgit v1.2.3-24-g4f1b