From 01e27fa34719b8e68def295c575bfb1f9b0ed362 Mon Sep 17 00:00:00 2001 From: Kevin Morris Date: Fri, 29 Oct 2021 20:29:56 -0700 Subject: [PATCH] fix(fastapi): sanitize /requests params Signed-off-by: Kevin Morris --- aurweb/routers/packages.py | 2 ++ 1 file changed, 2 insertions(+) diff --git a/aurweb/routers/packages.py b/aurweb/routers/packages.py index 14b91221..27125b60 100644 --- a/aurweb/routers/packages.py +++ b/aurweb/routers/packages.py @@ -635,6 +635,8 @@ async def requests(request: Request, context = make_context(request, "Requests") context["q"] = dict(request.query_params) + + O, PP = util.sanitize_params(O, PP) context["O"] = O context["PP"] = PP