]> git.sesse.net Git - pr0n/blobdiff - perl/Sesse/pr0n/Common.pm
Fix a few XSS-ish issues.
[pr0n] / perl / Sesse / pr0n / Common.pm
index 024d220f4628dd39df35a4deeb8cd5d2b3efd8a6..073996f187bc06783d1dc8ac8c27019e6974d691 100644 (file)
@@ -24,6 +24,7 @@ use LWP::Simple;
 # use Image::Info;
 use Image::ExifTool;
 use HTML::Entities;
+use URI::Escape;
 
 BEGIN {
        use Exporter ();
@@ -129,6 +130,12 @@ sub get_query_string {
        while (my ($key, $value) = each %$param) {
                next unless defined($value);
                next if (defined($defparam->{$key}) && $value == $defparam->{$key});
+
+               $value = URI::Escape::uri_escape($value);
+
+               # Unescape a few for prettiness (we'll need something for a real _, though)
+               $value =~ s/%20/_/g;
+               $value =~ s/%2F/\//g;
        
                $str .= ($first) ? "?" : ';';
                $str .= "$key=$value";
@@ -404,7 +411,7 @@ sub ensure_cached {
                                        $parms{'interlace'} = 'Plane';
                                }
                                if (defined($sf)) {
-                                       $parms{'scaling-factor'} = $sf;
+                                       $parms{'sampling-factor'} = $sf;
                                }
                                $err = $cimg->write(%parms);
                        }