-
-
Notifications
You must be signed in to change notification settings - Fork 695
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Database/Table/Row not found errors echo back text from URL #2359
Comments
Code at fault: Lines 1615 to 1622 in 93534fd
|
simonw
added a commit
that referenced
this issue
Jun 21, 2024
simonw
added a commit
that referenced
this issue
Jun 21, 2024
simonw
added a commit
that referenced
this issue
Jun 21, 2024
simonw
changed the title
Database not found error echoes back text from URL
Database/Table/Row not found errors echo back text from URL
Jun 21, 2024
The fix for |
Fix is deployed on |
Shipped in 0.64.8: https://docs.datasette.io/en/stable/changelog.html#v0-64-8 It's live in Datasette Lite already: https://lite.datasette.io/#/content/this+will+not+be+displayed |
Closed
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
This was raised in Discord. The returned error message is escaped, so this isn't an XSS error, but it could still be used to create a confusing error message like so:
The text was updated successfully, but these errors were encountered: