]> WPIA git - gigi.git/blobdiff - src/org/cacert/gigi/output/template/SprintfCommand.java
Escape template var output.
[gigi.git] / src / org / cacert / gigi / output / template / SprintfCommand.java
index 42ed9570d514fd3498c7ddd1504b50a3c4dce6e9..f0a3f35917368cc05e1c929cda9c549050a11eea 100644 (file)
@@ -6,24 +6,32 @@ import java.util.Map;
 
 import org.cacert.gigi.Language;
 import org.cacert.gigi.output.Outputable;
+import org.cacert.gigi.util.HTMLEncoder;
 
 public final class SprintfCommand implements Outputable {
-       private final String text;
-       private final LinkedList<String> store;
 
-       public SprintfCommand(String text, LinkedList<String> store) {
-               this.text = text;
-               this.store = store;
-       }
+    private final String text;
 
-       @Override
-       public void output(PrintWriter out, Language l, Map<String, Object> vars) {
-               String[] parts = l.getTranslation(text).split("%s");
-               String[] myvars = store.toArray(new String[store.size()]);
-               out.print(parts[0]);
-               for (int j = 1; j < parts.length; j++) {
-                       Template.outputVar(out, l, vars, myvars[j - 1].substring(1));
-                       out.print(parts[j]);
-               }
-       }
-}
\ No newline at end of file
+    private final LinkedList<String> store;
+
+    public SprintfCommand(String text, LinkedList<String> store) {
+        this.text = text;
+        this.store = store;
+    }
+
+    @Override
+    public void output(PrintWriter out, Language l, Map<String, Object> vars) {
+        String[] parts = l.getTranslation(text).split("%s");
+        String[] myvars = store.toArray(new String[store.size()]);
+        out.print(HTMLEncoder.encodeHTML(parts[0]));
+        for (int j = 1; j < parts.length; j++) {
+            String var = myvars[j - 1];
+            if (var.startsWith("$!")) {
+                Template.outputVar(out, l, vars, myvars[j - 1].substring(2), true);
+            } else {
+                Template.outputVar(out, l, vars, myvars[j - 1].substring(1), false);
+            }
+            out.print(HTMLEncoder.encodeHTML(parts[j]));
+        }
+    }
+}