diff --git a/lib/galaxy/datatypes/data.py b/lib/galaxy/datatypes/data.py
index 9b20f43a03a..e8aa5c6b13b 100644
--- a/lib/galaxy/datatypes/data.py
+++ b/lib/galaxy/datatypes/data.py
@@ -372,7 +372,7 @@ class Data(object):
tmp_file_name = tmp_fh.name
dir_items = sorted(os.listdir(file_path))
base_path, item_name = os.path.split(file_path)
- tmp_fh.write('
Directory %s contents: %d items
\n' % (item_name, len(dir_items)))
+ tmp_fh.write('Directory %s contents: %d items
\n' % (escape(item_name), len(dir_items)))
tmp_fh.write('\n')
for index, fname in enumerate(dir_items):
if index % 2 == 0:
@@ -386,10 +386,10 @@ class Data(object):
# href = url_for(controller='dataset', action='display',
# dataset_id=trans.security.encode_id(data.dataset.id),
# preview=preview, filename=fname, to_ext=to_ext)
- tmp_fh.write('| %s |
\n' % (bgcolor, fname))
+ tmp_fh.write('| %s |
\n' % (bgcolor, escape(fname)))
tmp_fh.write('
\n')
tmp_fh.close()
- return open(tmp_file_name)
+ return self._yield_user_file_content(trans, data, file_path)
mime = mimetypes.guess_type(file_path)[0]
if not mime:
try:
@@ -443,22 +443,6 @@ class Data(object):
return open(filename)
- def _yield_user_file_content(self, trans, from_dataset, filename):
- """This method is responsible for sanitizing the HTML if needed."""
- if trans.app.config.sanitize_all_html and trans.response.get_content_type() == "text/html":
- # Sanitize anytime we respond with plain text/html content.
- # Check to see if this dataset's parent job is whitelisted
- # We cannot currently trust imported datasets for rendering.
- if not from_dataset.creating_job.imported and from_dataset.creating_job.tool_id in trans.app.config.sanitize_whitelist:
- return open(filename)
-
- # This is returning to the browser, it needs to be encoded.
- # TODO Ideally this happens a layer higher, but this is a bad
- # issue affecting many tools
- return sanitize_html(open(filename).read()).encode('utf-8')
-
- return open(filename)
-
def _download_filename(self, dataset, to_ext, hdca=None, element_identifier=None):
def escape(raw_identifier):
return ''.join(c in FILENAME_VALID_CHARS and c or '_' for c in raw_identifier)[0:150]