From 56d054e6348a7806dd2591562d7738f1aa0bb002 Mon Sep 17 00:00:00 2001 From: Tom Christie Date: Mon, 3 Nov 2014 11:06:45 +0000 Subject: [PATCH] Proper escaping of URLs when replacing query parameter --- rest_framework/templatetags/rest_framework.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rest_framework/templatetags/rest_framework.py b/rest_framework/templatetags/rest_framework.py index d9424f022..7251f0711 100644 --- a/rest_framework/templatetags/rest_framework.py +++ b/rest_framework/templatetags/rest_framework.py @@ -23,7 +23,7 @@ def replace_query_param(url, key, val): query_dict = QueryDict(query).copy() query_dict[key] = val query = query_dict.urlencode() - return urlparse.urlunsplit((scheme, netloc, path, query, fragment)) + return escape(urlparse.urlunsplit((scheme, netloc, path, query, fragment))) # Regex for adding classes to html snippets