refresh tweaks

another escape html
This commit is contained in:
zzz
2014-07-26 20:14:01 +00:00
parent 1e0c970c95
commit d6b0b1b93c
4 changed files with 10 additions and 4 deletions

View File

@ -17,9 +17,14 @@
if (d == null || "".equals(d))
d = intl.getRefresh();
else {
d = net.i2p.data.DataHelper.stripHTML(d); // XSS
long delay;
try {
delay = Long.parseLong(d);
} catch (NumberFormatException nfe) {
delay = 60;
}
// pass the new delay parameter to the iframe
newDelay = "?refresh=" + d;
newDelay = "?refresh=" + delay;
// update disable boolean
intl.setDisableRefresh(d);
}