From 48d54317c053a7123b522abcd97732b93e4e747f Mon Sep 17 00:00:00 2001 From: mvdbeek Date: Thu, 4 Nov 2021 09:32:10 +0100 Subject: [PATCH] Fix action token sending for chracters that are escaped in html The function body of escape is ``` def escape(s): """Replace the characters ``&``, ``<``, ``>``, ``'``, and ``"`` in the string with HTML-safe sequences. Use this if you need to display text that might contain such characters in HTML. If the object has an ``__html__`` method, it is called and the return value is assumed to already be safe for HTML. :param s: An object to be converted to a string and escaped. :return: A :class:`Markup` string with the escaped text. """ if hasattr(s, "__html__"): return Markup(s.__html__()) return Markup( text_type(s) .replace("&", "&") .replace(">", ">") .replace("<", "<") .replace("'", "'") .replace('"', """) ) ``` It doesn't make sense to lookup the replaced values in the database, and it breaks single-quotes in the email username portion, which is valid https://en.wikipedia.org/wiki/Email_address#Syntax --- lib/galaxy/managers/users.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/galaxy/managers/users.py b/lib/galaxy/managers/users.py index cb9f4c67b73..0cef6a3bea0 100644 --- a/lib/galaxy/managers/users.py +++ b/lib/galaxy/managers/users.py @@ -488,7 +488,7 @@ class UserManager(base.ModelManager, deletable.PurgableManagerMixin): """ Send the verification email containing the activation link to the user's email. """ - activation_token = self.__get_activation_token(trans, escape(email)) + activation_token = self.__get_activation_token(trans, email) activation_link = url_for(controller='user', action='activate', activation_token=activation_token, email=escape(email), qualified=True) host = self.__get_host(trans) custom_message = ''