Escape anything that could be user input in mako templates, add markupsafe.escape to username and email in users API controller.

This commit is contained in:
Dave Bouvier
2014-12-10 11:31:21 -05:00
parent 9dddf84e69
commit 69ff4677bc
46 changed files with 200 additions and 190 deletions
+6 -3
View File
@@ -11,6 +11,7 @@ from galaxy.security.validate_user_input import validate_publicname
from galaxy.web.base.controller import BaseAPIController, UsesTagsMixin
from galaxy.web.base.controller import CreatesApiKeysMixin
from galaxy.web.base.controller import CreatesUsersMixin
from markupsafe import escape
log = logging.getLogger( __name__ )
@@ -38,10 +39,10 @@ class UserAPIController( BaseAPIController, UsesTagsMixin, CreatesUsersMixin, Cr
query = query.filter( trans.app.model.User.table.c.deleted == False ) # noqa
# special case: user can see only their own user
if not trans.user_is_admin():
item = trans.user.to_dict( value_mapper={ 'id': trans.security.encode_id } )
item = trans.user.to_dict( value_mapper={ 'id': trans.security.encode_id, 'email': escape } )
return [item]
for user in query:
item = user.to_dict( value_mapper={ 'id': trans.security.encode_id } )
item = user.to_dict( value_mapper={ 'id': trans.security.encode_id, 'email': escape } )
# TODO: move into api_values
rval.append( item )
return rval
@@ -78,7 +79,9 @@ class UserAPIController( BaseAPIController, UsesTagsMixin, CreatesUsersMixin, Cr
else:
raise HTTPBadRequest( detail='Invalid user id ( %s ) specified' % id )
item = user.to_dict( view='element', value_mapper={ 'id': trans.security.encode_id,
'total_disk_usage': float } )
'total_disk_usage': float,
'email': escape,
'username': escape } )
# add a list of tags used by the user (as strings)
item[ 'tags_used' ] = self.get_user_tags_used( trans, user=user )
# TODO: move into api_values (needs trans, tho - can we do that with api_keys/@property??)
@@ -11,9 +11,9 @@
</%def>
<%def name="render_select( name, options )">
<select name="${name}" id="${name}" style="min-width: 250px; height: 150px;" multiple>
<select name="${name|h}" id="${name|h}" style="min-width: 250px; height: 150px;" multiple>
%for option in options:
<option value="${option[0]}">${option[1]}</option>
<option value="${option[0]|h}">${option[1]|h}</option>
%endfor
</select>
</%def>
@@ -48,29 +48,29 @@ $().ready(function() {
%endif
<div class="toolForm">
<div class="toolFormTitle">Group '${group.name}'</div>
<div class="toolFormTitle">Group '${group.name|h}'</div>
<div class="toolFormBody">
<form name="associate_group_role_user" id="associate_group_role_user" action="${h.url_for(controller='admin', action='manage_users_and_roles_for_group', id=trans.security.encode_id( group.id ) )}" method="post" >
<div class="form-row">
<div style="float: left; margin-right: 10px;">
<label>Roles associated with '${group.name}'</label>
<label>Roles associated with '${group.name|h}'</label>
${render_select( "in_roles", in_roles )}<br/>
<input type="submit" id="roles_remove_button" value=">>"/>
</div>
<div>
<label>Roles not associated with '${group.name}'</label>
<label>Roles not associated with '${group.name|h}'</label>
${render_select( "out_roles", out_roles )}<br/>
<input type="submit" id="roles_add_button" value="<<"/>
</div>
</div>
<div class="form-row">
<div style="float: left; margin-right: 10px;">
<label>Users associated with '${group.name}'</label>
<label>Users associated with '${group.name|h}'</label>
${render_select( "in_users", in_users )}<br/>
<input type="submit" id="users_remove_button" value=">>"/>
</div>
<div>
<label>Users not associated with '${group.name}'</label>
<label>Users not associated with '${group.name|h}'</label>
${render_select( "out_users", out_users )}<br/>
<input type="submit" id="users_add_button" value="<<"/>
</div>
@@ -11,9 +11,9 @@
</%def>
<%def name="render_select( name, options )">
<select name="${name}" id="${name}" style="min-width: 250px; height: 150px;" multiple>
<select name="${name|h}" id="${name|h}" style="min-width: 250px; height: 150px;" multiple>
%for option in options:
<option value="${option[0]}">${option[1]}</option>
<option value="${option[0]|h}">${option[1]|h}</option>
%endfor
</select>
</%def>
@@ -60,7 +60,7 @@ $().ready(function() {
<form name="associate_group_role_user" id="associate_group_role_user" action="${h.url_for(controller='admin', action='create_group' )}" method="post" >
<div class="form-row">
<label>Name:</label>
<input name="name" type="textfield" value="${name}" size=40"/>
<input name="name" type="textfield" value="${name|h}" size=40"/>
</div>
<div class="form-row">
<div style="float: left; margin-right: 10px;">
@@ -12,7 +12,7 @@
<div class="form-row">
<label>Name:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="name" value="${group.name}" size="40"/>
<input type="text" name="name" value="${group.name|h}" size="40"/>
</div>
<div style="clear: both"></div>
</div>
+11 -11
View File
@@ -11,9 +11,9 @@
</%def>
<%def name="render_select( name, options )">
<select name="${name}" id="${name}" style="min-width: 250px; height: 150px;" multiple>
<select name="${name|h}" id="${name|h}" style="min-width: 250px; height: 150px;" multiple>
%for option in options:
<option value="${option[0]}">${option[1]}</option>
<option value="${option[0]|h}">${option[1]|h}</option>
%endfor
</select>
</%def>
@@ -48,29 +48,29 @@ $().ready(function() {
%endif
<div class="toolForm">
<div class="toolFormTitle">Role '${role.name}'</div>
<div class="toolFormTitle">Role '${role.name|h}'</div>
<div class="toolFormBody">
<form name="associate_role_user_group" id="associate_role_user_group" action="${h.url_for(controller='admin', action='manage_users_and_groups_for_role', id=trans.security.encode_id( role.id ) )}" method="post" >
<div class="form-row">
<div style="float: left; margin-right: 10px;">
<label>Users associated with '${role.name}'</label>
<label>Users associated with '${role.name|h}'</label>
${render_select( "in_users", in_users )}<br/>
<input type="submit" id="users_remove_button" value=">>"/>
</div>
<div>
<label>Users not associated with '${role.name}'</label>
<label>Users not associated with '${role.name|h}'</label>
${render_select( "out_users", out_users )}<br/>
<input type="submit" id="users_add_button" value="<<"/>
</div>
</div>
<div class="form-row">
<div style="float: left; margin-right: 10px;">
<label>Groups associated with '${role.name}'</label>
<label>Groups associated with '${role.name|h}'</label>
${render_select( "in_groups", in_groups )}<br/>
<input type="submit" id="groups_remove_button" value=">>"/>
</div>
<div>
<label>Groups not associated with '${role.name}'</label>
<label>Groups not associated with '${role.name|h}'</label>
${render_select( "out_groups", out_groups )}<br/>
<input type="submit" id="groups_add_button" value="<<"/>
</div>
@@ -84,7 +84,7 @@ $().ready(function() {
<br clear="left"/>
<br/>
%if len( library_dataset_actions ) > 0:
<h3>Data library datasets associated with role '${role.name}'</h3>
<h3>Data library datasets associated with role '${role.name|h}'</h3>
<table class="manage-table colored" border="0" cellspacing="0" cellpadding="0" width="100%">
<tr>
<td>
@@ -92,16 +92,16 @@ $().ready(function() {
%for ctr, library, in enumerate( library_dataset_actions.keys() ):
<li>
<img src="${h.url_for( '/static/images/silk/book_open.png' )}" class="rowIcon"/>
${library.name}
${library.name|h}
<ul>
%for folder_path, permissions in library_dataset_actions[ library ].items():
<li>
<img src="/static/images/silk/folder_page.png" class="rowIcon"/>
${folder_path}
${folder_path|h}
<ul>
% for permission in permissions:
<ul>
<li>${permission}</li>
<li>${permission|h}</li>
</ul>
%endfor
</ul>
@@ -11,9 +11,9 @@
</%def>
<%def name="render_select( name, options )">
<select name="${name}" id="${name}" style="min-width: 250px; height: 150px;" multiple>
<select name="${name|h}" id="${name|h}" style="min-width: 250px; height: 150px;" multiple>
%for option in options:
<option value="${option[0]}">${option[1]}</option>
<option value="${option[0]|h}">${option[1]|h}</option>
%endfor
</select>
</%def>
@@ -60,11 +60,11 @@
<form name="associate_role_group_user" id="associate_role_group_user" action="${h.url_for(controller='admin', action='create_role' )}" method="post" >
<div class="form-row">
<label>Name:</label>
<input name="name" type="textfield" value="${name}" size=40"/>
<input name="name" type="textfield" value="${name|h}" size=40"/>
</div>
<div class="form-row">
<label>Description:</label>
<input name="description" type="textfield" value="${description}" size=40"/>
<input name="description" type="textfield" value="${description|h}" size=40"/>
</div>
<div class="form-row">
<div style="float: left; margin-right: 10px;">
@@ -12,14 +12,14 @@
<div class="form-row">
<label>Name:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="name" value="${role.name}" size="40"/>
<input type="text" name="name" value="${role.name|h}" size="40"/>
</div>
<div style="clear: both"></div>
</div>
<div class="form-row">
<label>Description:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input name="description" type="textfield" value="${role.description}" size=40"/>
<input name="description" type="textfield" value="${role.description|h}" size=40"/>
</div>
<div style="clear: both"></div>
</div>
@@ -12,10 +12,10 @@
%if widgets:
%for i, field in enumerate( widgets ):
<div class="form-row">
<label>${field['label']}:</label>
<label>${field['label']|h}:</label>
${field['widget'].get_html()}
<div class="toolParamHelp" style="clear: both;">
${field['helptext']}
${field['helptext']|h}
</div>
<div style="clear: both"></div>
</div>
@@ -25,10 +25,10 @@
<div class="toolFormTitle">Edit external service</div>
%for i, field in enumerate( widgets ):
<div class="form-row">
<label>${field['label']}:</label>
<label>${field['label']|h}:</label>
${field['widget'].get_html()}
<div class="toolParamHelp" style="clear: both;">
${field['helptext']}
${field['helptext']|h}
</div>
<div style="clear: both"></div>
</div>
+9 -9
View File
@@ -63,12 +63,12 @@
</td>
<td>${job.id}</td>
%if job.history and job.history.user:
<td>${job.history.user.email}</td>
<td>${job.history.user.email|h}</td>
%else:
<td>anonymous</td>
%endif
<td>${last_updated[job.id]} ago</td>
<td>${job.tool_id}</td>
<td>${job.tool_id|h}</td>
<td>${job.state}</td>
<%
try:
@@ -77,8 +77,8 @@
inputs = 'Unable to determine inputs'
%>
<td>${inputs}</td>
<td>${job.command_line}</td>
<td>${job.job_runner_name}</td>
<td>${job.command_line|h}</td>
<td>${job.job_runner_name|h}</td>
<td>${job.job_runner_external_id}</td>
</tr>
%endfor
@@ -131,12 +131,12 @@
%for job in recent_jobs:
<td><a href="${h.url_for( controller="admin", action="job_info" )}?jobid=${job.id}">${job.id}</a></td>
%if job.history and job.history.user:
<td>${job.history.user.email}</td>
<td>${job.history.user.email|h}</td>
%else:
<td>anonymous</td>
%endif
<td>${finished[job.id]} ago</td>
<td>${job.tool_id}</td>
<td>${job.tool_id|h}</td>
<td>${job.state}</td>
<%
try:
@@ -145,9 +145,9 @@
inputs = 'Unable to determine inputs'
%>
<td>${inputs}</td>
<td>${job.command_line}</td>
<td>${job.job_runner_name}</td>
<td>${job.job_runner_external_id}</td>
<td>${job.command_line|h}</td>
<td>${job.job_runner_name|h}</td>
<td>${job.job_runner_external_id|h}</td>
</tr>
%endfor
</table>
+1 -1
View File
@@ -55,7 +55,7 @@
<br/>
You are here: ${breadcrumb}<br/>
%if breadcrumb.endswith( 'theone' ):
${heap}
${heap|h}
%else:
<nobr>
Sort:
+3 -3
View File
@@ -28,9 +28,9 @@ $().ready(function() {
<select name="tool_id">
%for key, val in toolbox.tool_panel.items():
%if isinstance( val, Tool ):
<option value="${val.id}">${val.name}</option>
<option value="${val.id|h}">${val.name|h}</option>
%elif isinstance( val, ToolSection ):
<optgroup label="${val.name}">
<optgroup label="${val.name|h}">
<% section = val %>
%for section_key, section_val in section.elems.items():
%if isinstance( section_val, Tool ):
@@ -38,7 +38,7 @@ $().ready(function() {
%if section_val.id == tool_id:
<% selected_str = " selected=\"selected\"" %>
%endif
<option value="${section_val.id}"${selected_str}>${section_val.name}</option>
<option value="${section_val.id|h}"${selected_str}>${section_val.name|h}</option>
%endif
%endfor
%endif
+7 -7
View File
@@ -11,9 +11,9 @@
</%def>
<%def name="render_select( name, options )">
<select name="${name}" id="${name}" style="min-width: 250px; height: 150px;" multiple>
<select name="${name|h}" id="${name|h}" style="min-width: 250px; height: 150px;" multiple>
%for option in options:
<option value="${option[0]}">${option[1]}</option>
<option value="${option[0]|h}">${option[1]|h}</option>
%endfor
</select>
</%def>
@@ -48,29 +48,29 @@ $().ready(function() {
%endif
<div class="toolForm">
<div class="toolFormTitle">Quota '${name}'</div>
<div class="toolFormTitle">Quota '${name|h}'</div>
<div class="toolFormBody">
<form name="associate_quota_user_group" id="associate_quota_user_group" action="${h.url_for(controller='admin', action='manage_users_and_groups_for_quota', id=id )}" method="post" >
<div class="form-row">
<div style="float: left; margin-right: 10px;">
<label>Users associated with '${name}'</label>
<label>Users associated with '${name|h}'</label>
${render_select( "in_users", in_users )}<br/>
<input type="submit" id="users_remove_button" value=">>"/>
</div>
<div>
<label>Users not associated with '${name}'</label>
<label>Users not associated with '${name|h}'</label>
${render_select( "out_users", out_users )}<br/>
<input type="submit" id="users_add_button" value="<<"/>
</div>
</div>
<div class="form-row">
<div style="float: left; margin-right: 10px;">
<label>Groups associated with '${name}'</label>
<label>Groups associated with '${name|h}'</label>
${render_select( "in_groups", in_groups )}<br/>
<input type="submit" id="groups_remove_button" value=">>"/>
</div>
<div>
<label>Groups not associated with '${name}'</label>
<label>Groups not associated with '${name|h}'</label>
${render_select( "out_groups", out_groups )}<br/>
<input type="submit" id="groups_add_button" value="<<"/>
</div>
+5 -5
View File
@@ -11,9 +11,9 @@
</%def>
<%def name="render_select( name, options )">
<select name="${name}" id="${name}" style="min-width: 250px; height: 150px;" multiple>
<select name="${name|h}" id="${name|h}" style="min-width: 250px; height: 150px;" multiple>
%for option in options:
<option value="${option[0]}">${option[1]}</option>
<option value="${option[0]|h}">${option[1]|h}</option>
%endfor
</select>
</%def>
@@ -69,15 +69,15 @@
<form name="associate_quota_group_user" id="associate_quota_group_user" action="${h.url_for(controller='admin', action='create_quota' )}" method="post" >
<div class="form-row">
<label>Name:</label>
<input name="name" type="textfield" value="${name}" size=40"/>
<input name="name" type="textfield" value="${name|h}" size=40"/>
</div>
<div class="form-row">
<label>Description:</label>
<input name="description" type="textfield" value="${description}" size=40"/>
<input name="description" type="textfield" value="${description|h}" size=40"/>
</div>
<div class="form-row">
<label>Amount</label>
<input name="amount" type="textfield" value="${amount}" size=40"/>
<input name="amount" type="textfield" value="${amount|h}" size=40"/>
<div class="toolParamHelp" style="clear: both;">
Examples: "10000MB", "99 gb", "0.2T", "unlimited"
</div>
+1 -1
View File
@@ -29,7 +29,7 @@
<input name="id" type="hidden" value="${id}"/>
<div class="form-row">
<label>Amount</label>
<input name="amount" type="textfield" value="${display_amount}" size=40"/>
<input name="amount" type="textfield" value="${display_amount|h}" size=40"/>
<div class="toolParamHelp" style="clear: both;">
Examples: "10000MB", "99 gb", "0.2T", "unlimited"
</div>
+2 -2
View File
@@ -21,14 +21,14 @@
<div class="form-row">
<label>Name:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input type="text" name="name" value="${name}" size="40"/>
<input type="text" name="name" value="${name|h}" size="40"/>
</div>
<div style="clear: both"></div>
</div>
<div class="form-row">
<label>Description:</label>
<div style="float: left; width: 250px; margin-right: 10px;">
<input name="description" type="textfield" value="${description}" size=40"/>
<input name="description" type="textfield" value="${description|h}" size=40"/>
</div>
<div style="clear: both"></div>
</div>
+3 -3
View File
@@ -28,9 +28,9 @@ $().ready(function() {
<select name="tool_id">
%for key, val in toolbox.tool_panel.items():
%if isinstance( val, Tool ):
<option value="${val.id}">${val.name}</option>
<option value="${val.id}">${val.name|h}</option>
%elif isinstance( val, ToolSection ):
<optgroup label="${val.name}">
<optgroup label="${val.name|h}">
<% section = val %>
%for section_key, section_val in section.elems.items():
%if isinstance( section_val, Tool ):
@@ -38,7 +38,7 @@ $().ready(function() {
%if section_val.id == tool_id:
<% selected_str = " selected=\"selected\"" %>
%endif
<option value="${section_val.id}"${selected_str}>${section_val.name}</option>
<option value="${section_val.id}"${selected_str}>${section_val.name|h}</option>
%endif
%endfor
%endif
@@ -4,7 +4,9 @@
%if message:
${render_msg( message, status )}
%endif
<%
from markupsafe import escape
%>
<div class="toolForm">
<div class="toolFormTitle">Tool migrations that can be performed on this Galaxy instance</div>
<div class="toolFormBody">
@@ -51,7 +53,7 @@
repository_names.sort()
repository_names = ', '.join( repository_names )
%>
<tr><td bgcolor="#D8D8D8"><b>Tool migration stage ${stage} - repositories: ${repository_names}</b></td></tr>
<tr><td bgcolor="#D8D8D8"><b>Tool migration stage ${stage} - repositories: ${repository_names|h}</b></td></tr>
<tr>
<td bgcolor="#FFFFCC">
<div class="form-row">
@@ -59,11 +61,11 @@
<p>
%if tool_dependencies:
This migration stage includes tools that have tool dependencies that can be automatically installed. To install them, run:<br/>
<b>${install_dependencies}</b><br/><br/>
<b>${install_dependencies|h}</b><br/><br/>
To skip tool dependency installation run:<br/>
<b>${migration_command}</b>
<b>${migration_command|h}</b>
%else:
<b>${migration_command}</b>
<b>${migration_command|h}</b>
%endif
</p>
</div>
@@ -74,7 +76,7 @@
<tr>
<td bgcolor="#DADFEF">
<div class="form-row">
<b>Repository:</b> ${repository_name}
<b>Repository:</b> ${repository_name|h}
</div>
</td>
</tr>
@@ -88,10 +90,10 @@
</tr>
%for tool_dependencies_tup in tool_dependencies:
<%
tool_dependency_name = tool_dependencies_tup[0]
tool_dependency_version = tool_dependencies_tup[1]
tool_dependency_type = tool_dependencies_tup[2]
installation_requirements = tool_dependencies_tup[3].replace( '\n', '<br/>' )
tool_dependency_name = escape( tool_dependencies_tup[0] )
tool_dependency_version = escape( tool_dependencies_tup[1] )
tool_dependency_type = escape( tool_dependencies_tup[2] )
installation_requirements = escape( tool_dependencies_tup[3] ).replace( '\n', '<br/>' )
%>
<tr>
<td>
@@ -21,7 +21,7 @@ ${render_galaxy_repository_actions( repository )}
%endif
<div class="toolForm">
<div class="toolFormTitle">Browse ${repository.name} revision ${repository.changeset_revision} files</div>
<div class="toolFormTitle">Browse ${repository.name|h} revision ${repository.changeset_revision} files</div>
<div class="toolFormBody">
<div class="form-row" >
<label>Contents:</label>
@@ -23,33 +23,33 @@ ${render_galaxy_repository_actions( repository )}
%endif
<div class="toolForm">
<div class="toolFormTitle">Browse tool dependency ${tool_dependency.name} installation directory</div>
<div class="toolFormTitle">Browse tool dependency ${tool_dependency.name|h} installation directory</div>
<div class="toolFormBody">
<div class="form-row" >
<label>Tool shed repository:</label>
${repository.name}
${repository.name|h}
<div style="clear: both"></div>
</div>
<div class="form-row" >
<label>Tool shed repository changeset revision:</label>
${repository.changeset_revision}
${repository.changeset_revision|h}
<div style="clear: both"></div>
</div>
<div class="form-row" >
<label>Tool dependency status:</label>
${tool_dependency.status}
${tool_dependency.status|h}
<div style="clear: both"></div>
</div>
%if tool_dependency.in_error_state:
<div class="form-row" >
<label>Tool dependency installation error:</label>
${tool_dependency.error_message}
${tool_dependency.error_message|h}
<div style="clear: both"></div>
</div>
%endif
<div class="form-row" >
<label>Tool dependency installation directory:</label>
${tool_dependency.installation_directory( trans.app )}
${tool_dependency.installation_directory( trans.app )|h}
<div style="clear: both"></div>
</div>
<div class="form-row" >
@@ -8,7 +8,7 @@
});
// --- Initialize sample trees
$("#tree").dynatree({
title: "${title_text}",
title: "${title_text|h}",
rootVisible: true,
minExpandLevel: 0, // 1: root node is not collapsible
persist: false,
@@ -24,7 +24,7 @@
// initAjax is hard to fake, so we pass the children as object array:
initAjax: {url: "${h.url_for( controller='admin_toolshed', action='open_folder' )}",
dataType: "json",
data: { folder_path: "${directory_path}" },
data: { folder_path: "${directory_path|h}" },
},
onLazyRead: function(dtnode){
dtnode.appendAjax({
@@ -45,7 +45,7 @@
var cell = $("#file_contents");
var selected_value;
if (dtnode.data.key == 'root') {
selected_value = "${directory_path}/";
selected_value = "${directory_path|h}/";
} else {
selected_value = dtnode.data.key;
};
@@ -81,6 +81,7 @@
line-break:strict; }
</style>
<%
from markupsafe import escape
class RowCounter( object ):
def __init__( self ):
self.count = 0
@@ -96,7 +97,7 @@
env_settings_heaader_row_displayed = False
package_header_row_displayed = False
if revision_label:
revision_label_str = ' revision <b>%s</b> of ' % str( revision_label )
revision_label_str = ' revision <b>%s</b> of ' % escape( str( revision_label ) )
else:
revision_label_str = ' '
%>
@@ -104,7 +105,7 @@
<div class="toolParamHelp" style="clear: both;">
<p>
%if export:
The following additional repositories are required by${revision_label_str}the <b>${repository.name}</b> repository
The following additional repositories are required by${revision_label_str}the <b>${repository.name|h}</b> repository
and they can be exported as well.
%else:
These dependencies can be automatically handled with${revision_label_str}the installed repository, providing significant
@@ -10,30 +10,30 @@ ${render_galaxy_repository_actions( repository )}
%endif
<div class="toolForm">
<div class="toolFormTitle">${repository.name}</div>
<div class="toolFormTitle">${repository.name|h}</div>
<div class="toolFormBody">
<form name="deactivate_or_uninstall_repository" id="deactivate_or_uninstall_repository" action="${h.url_for( controller='admin_toolshed', action='deactivate_or_uninstall_repository', id=trans.security.encode_id( repository.id ) )}" method="post" >
<div class="form-row">
<label>Description:</label>
${repository.description}
${repository.description|h}
<div style="clear: both"></div>
</div>
<div class="form-row">
<label>Revision:</label>
${repository.changeset_revision}</a>
${repository.changeset_revision|h}</a>
</div>
<div class="form-row">
<label>Tool shed:</label>
${repository.tool_shed}
${repository.tool_shed|h}
<div style="clear: both"></div>
</div>
<div class="form-row">
<label>Owner:</label>
${repository.owner}
${repository.owner|h}
</div>
<div class="form-row">
<label>Deleted:</label>
${repository.deleted}
${repository.deleted|h}
</div>
<div class="form-row">
<%
@@ -186,7 +186,7 @@ ${render_galaxy_repository_actions( repository )}
##hack to mimic check box
<input type="hidden" name="remove_from_disk" value="true"/><input type="hidden" name="remove_from_disk" value="true"/>
%endif
<input type="submit" name="deactivate_or_uninstall_repository_button" value="${deactivate_uninstall_button_text}"/>
<input type="submit" name="deactivate_or_uninstall_repository_button" value="${deactivate_uninstall_button_text|h}"/>
</div>
</form>
</div>
@@ -53,18 +53,18 @@
<td>
%if link_to_manage_tool_dependencies:
<a class="view-info" href="${h.url_for( controller='admin_toolshed', action='manage_tool_dependencies', tool_dependency_ids=ids_of_tool_dependencies_missing_or_being_installed )}">
${tool_shed_repository.name}
${tool_shed_repository.name|h}
</a>
%else:
<a class="view-info" href="${h.url_for( controller='admin_toolshed', action='manage_repository', id=encoded_repository_id )}">
${tool_shed_repository.name}
${tool_shed_repository.name|h}
</a>
%endif
</td>
<td>${tool_shed_repository.description}</td>
<td>${tool_shed_repository.owner}</td>
<td>${tool_shed_repository.changeset_revision}</td>
<td><div id="RepositoryStatus-${encoded_repository_id}">${tool_shed_repository.status}</div></td>
<td><div id="RepositoryStatus-${encoded_repository_id}">${tool_shed_repository.status|h}</div></td>
</tr>
%endfor
</table>
@@ -20,12 +20,12 @@ ${render_galaxy_repository_actions( repository )}
<div class="toolForm">
<div class="toolFormBody">
<form name="install_tool_dependencies_with_update" id="install_tool_dependencies_with_update" action="${h.url_for( controller='admin_toolshed', action='install_tool_dependencies_with_update' )}" method="post" >
<input type="hidden" name="updating_repository_id" value="${updating_repository_id}"/>
<input type="hidden" name="updating_to_ctx_rev" value="${updating_to_ctx_rev}"/>
<input type="hidden" name="updating_to_changeset_revision" value="${updating_to_changeset_revision}"/>
<input type="hidden" name="encoded_updated_metadata" value="${encoded_updated_metadata}"/>
<input type="hidden" name="encoded_relative_install_dir" value="${encoded_relative_install_dir}"/>
<input type="hidden" name="encoded_tool_dependencies_dict" value="${encoded_tool_dependencies_dict}"/>
<input type="hidden" name="updating_repository_id" value="${updating_repository_id|h}"/>
<input type="hidden" name="updating_to_ctx_rev" value="${updating_to_ctx_rev|h}"/>
<input type="hidden" name="updating_to_changeset_revision" value="${updating_to_changeset_revision|h}"/>
<input type="hidden" name="encoded_updated_metadata" value="${encoded_updated_metadata|h}"/>
<input type="hidden" name="encoded_relative_install_dir" value="${encoded_relative_install_dir|h}"/>
<input type="hidden" name="encoded_tool_dependencies_dict" value="${encoded_tool_dependencies_dict|h}"/>
%if tool_dependencies_dict:
%if install_tool_dependencies_check_box is not None:
<div class="form-row">
@@ -71,12 +71,12 @@ ${render_galaxy_repository_actions( repository )}
%>
%if not os.path.exists( install_dir ):
<tr>
<td>${key_name}</td>
<td>${key_version}</td>
<td>${install_dir}</td>
<td>${key_name|h}</td>
<td>${key_version|h}</td>
<td>${install_dir|h}</td>
</tr>
%if readme_text:
<tr><td colspan="4" bgcolor="#FFFFCC">${key_name} ${key_version} requirements and installation information</td></tr>
<tr><td colspan="4" bgcolor="#FFFFCC">${key_name|h} ${key_version|h} requirements and installation information</td></tr>
<tr><td colspan="4"><pre>${readme_text}</pre></td></tr>
%endif
%endif
@@ -22,50 +22,50 @@ ${render_galaxy_repository_actions( repository )}
%endif
<div class="toolForm">
<div class="toolFormTitle">Installed tool shed repository '${repository.name}'</div>
<div class="toolFormTitle">Installed tool shed repository '${repository.name|h}'</div>
<div class="toolFormBody">
<form name="edit_repository" id="edit_repository" action="${h.url_for( controller='admin_toolshed', action='manage_repository', id=trans.security.encode_id( repository.id ) )}" method="post" >
<div class="form-row">
<label>Tool shed:</label>
${repository.tool_shed}
${repository.tool_shed|h}
<div style="clear: both"></div>
</div>
<div class="form-row">
<label>Name:</label>
${repository.name}
${repository.name|h}
<div style="clear: both"></div>
</div>
<div class="form-row">
<label>Description:</label>
%if in_error_state:
${description}
${description|h}
%else:
<input name="description" type="textfield" value="${description}" size="80"/>
<input name="description" type="textfield" value="${description|h}" size="80"/>
%endif
<div style="clear: both"></div>
</div>
<div class="form-row">
<label>Revision:</label>
${repository.changeset_revision}
${repository.changeset_revision|h}
</div>
<div class="form-row">
<label>Owner:</label>
${repository.owner}
${repository.owner|h}
</div>
%if in_error_state:
<div class="form-row">
<label>Repository installation error:</label>
${repository.error_message}
${repository.error_message|h}
</div>
%else:
<div class="form-row">
<label>Location:</label>
${repo_files_dir}
${repo_files_dir|h}
</div>
%endif
<div class="form-row">
<label>Deleted:</label>
${repository.deleted}
${repository.deleted|h}
</div>
%if not in_error_state:
<div class="form-row">
@@ -20,7 +20,7 @@ ${render_galaxy_repository_actions( repository )}
%endif
<div class="toolForm">
<div class="toolFormTitle">Tool shed repository '${repository.name}' tool dependencies</div>
<div class="toolFormTitle">Tool shed repository '${repository.name|h}' tool dependencies</div>
<%
can_install = False
can_uninstall = False
@@ -48,16 +48,16 @@ ${render_galaxy_repository_actions( repository )}
<td>
%if tool_dependency.status not in [ trans.install_model.ToolDependency.installation_status.UNINSTALLED ]:
<a target="galaxy_main" href="${h.url_for( controller='admin_toolshed', action='manage_repository_tool_dependencies', operation='browse', tool_dependency_ids=trans.security.encode_id( tool_dependency.id ), repository_id=trans.security.encode_id( repository.id ) )}">
${tool_dependency.name}
${tool_dependency.name|h}
</a>
%else:
${tool_dependency.name}
${tool_dependency.name|h}
%endif
</td>
<td>${tool_dependency.version}</td>
<td>${tool_dependency.type}</td>
<td>${tool_dependency.status}</td>
<td>${error_message}</td>
<td>${tool_dependency.version|h}</td>
<td>${tool_dependency.type|h}</td>
<td>${tool_dependency.status|h}</td>
<td>${error_message|h}</td>
</tr>
%endfor
</table>
@@ -19,14 +19,14 @@ ${render_galaxy_repository_actions( repository )}
<div class="warningmessage">
<p>
Purging the repository named <b>${repository.name}</b> will result in deletion of all records for the
Purging the repository named <b>${repository.name|h}</b> will result in deletion of all records for the
following associated items from the database. Click the <b>Purge</b> button to purge this repository
and its associated items.
</p>
</div>
<div class="toolForm">
<div class="toolFormTitle">Purge tool shed repository <b>${repository.name}</b></div>
<div class="toolFormTitle">Purge tool shed repository <b>${repository.name|h}</b></div>
<form name="purge_repository" id="purge_repository" action="${h.url_for( controller='admin_toolshed', action='purge_repository', id=trans.security.encode_id( repository.id ) )}" method="post" >
<%
tool_versions = 0
@@ -59,11 +59,11 @@ ${render_galaxy_repository_actions( repository )}
orphan_repository_dependency_records += 1
%>
<table class="grid">
<tr><td>Tool version records</td><td>${tool_versions}</td><tr>
<tr><td>Tool dependency records</td><td>${tool_dependencies}</td><tr>
<tr><td>Repository dependency records</td><td>${required_repositories}</td><tr>
<tr><td>Orphan repository_repository_dependency_association records</td><td>${orphan_repository_repository_dependency_association_records}</td><tr>
<tr><td>Orphan repository_dependency records</td><td>${orphan_repository_dependency_records}</td><tr>
<tr><td>Tool version records</td><td>${tool_versions|h}</td><tr>
<tr><td>Tool dependency records</td><td>${tool_dependencies|h}</td><tr>
<tr><td>Repository dependency records</td><td>${required_repositories|h}</td><tr>
<tr><td>Orphan repository_repository_dependency_association records</td><td>${orphan_repository_repository_dependency_association_records|h}</td><tr>
<tr><td>Orphan repository_dependency records</td><td>${orphan_repository_dependency_records|h}</td><tr>
</table>
<div style="clear: both"></div>
<div class="form-row">
@@ -37,9 +37,9 @@ ${render_galaxy_repository_actions( repository )}
</div>
<div class="toolForm">
<div class="toolFormTitle">Repair tool shed repository <b>${repository.name}</b></div>
<div class="toolFormTitle">Repair tool shed repository <b>${repository.name|h}</b></div>
<form name="repair_repository" id="repair_repository" action="${h.url_for( controller='admin_toolshed', action='repair_repository', id=trans.security.encode_id( repository.id ) )}" method="post" >
<input type="hidden" name="repair_dict" value="${encoded_repair_dict}"/>
<input type="hidden" name="repair_dict" value="${encoded_repair_dict|h}"/>
<%
from tool_shed.util.shed_util_common import get_tool_shed_repository_status_label
ordered_repo_info_dicts = repair_dict.get( 'ordered_repo_info_dicts', [] )
@@ -1,5 +1,6 @@
<%def name="render_repository_status( repository )">
<%
from markupsafe import escape
if repository.status in [ trans.install_model.ToolShedRepository.installation_status.CLONING,
trans.install_model.ToolShedRepository.installation_status.SETTING_TOOL_VERSIONS,
trans.install_model.ToolShedRepository.installation_status.INSTALLING_TOOL_DEPENDENCIES,
@@ -20,7 +21,7 @@
else:
bgcolor = trans.install_model.ToolShedRepository.states.ERROR
rval = '<div class="count-box state-color-%s" id="RepositoryStatus-%s">' % ( bgcolor, trans.security.encode_id( repository.id ) )
rval += '%s</div>' % repository.status
rval += '%s</div>' % escape( repository.status )
return rval
%>
${rval}
@@ -62,12 +62,12 @@
<label>Shed tool configuration file:</label>
${shed_tool_conf_select_field.get_html()}
<div class="toolParamHelp" style="clear: both;">
${select_help}
${select_help|h}
</div>
</div>
<div style="clear: both"></div>
%else:
<input type="hidden" name="shed_tool_conf" value="${shed_tool_conf}"/>
<input type="hidden" name="shed_tool_conf" value="${shed_tool_conf|h}"/>
%endif
%if includes_tools_for_display_in_tool_panel:
<div style="clear: both"></div>
@@ -71,7 +71,7 @@
<input type="hidden" name="includes_tools" value="${includes_tools}" />
<input type="hidden" name="includes_tool_dependencies" value="${includes_tool_dependencies}" />
<input type="hidden" name="includes_tools_for_display_in_tool_panel" value="${includes_tools_for_display_in_tool_panel}" />
<input type="hidden" name="tool_shed_url" value="${tool_shed_url}" />
<input type="hidden" name="tool_shed_url" value="${tool_shed_url|h}" />
</div>
<div style="clear: both"></div>
<% readme_files_dict = containers_dict.get( 'readme_files', None ) %>
@@ -111,12 +111,12 @@
<label>Shed tool configuration file:</label>
${shed_tool_conf_select_field.get_html()}
<div class="toolParamHelp" style="clear: both;">
${select_help}
${select_help|h}
</div>
</div>
<div style="clear: both"></div>
%else:
<input type="hidden" name="shed_tool_conf" value="${shed_tool_conf}"/>
<input type="hidden" name="shed_tool_conf" value="${shed_tool_conf|h}"/>
%endif
<div class="form-row">
<input type="submit" name="select_shed_tool_panel_config_button" value="Install"/>
@@ -111,16 +111,16 @@
<label>Shed tool configuration file:</label>
${shed_tool_conf_select_field.get_html()}
<div class="toolParamHelp" style="clear: both;">
${select_help}
${select_help|h}
</div>
</div>
<div style="clear: both"></div>
%else:
<input type="hidden" name="shed_tool_conf" value="${shed_tool_conf}"/>
<input type="hidden" name="shed_tool_conf" value="${shed_tool_conf|h}"/>
%endif
<div class="form-row">
<label>Add new tool panel section:</label>
<input name="new_tool_panel_section_label" type="textfield" value="${new_tool_panel_section_label}" size="40"/>
<input name="new_tool_panel_section_label" type="textfield" value="${new_tool_panel_section_label|h}" size="40"/>
<div class="toolParamHelp" style="clear: both;">
Add a new tool panel section to contain the installed tools (optional).
</div>
@@ -43,10 +43,10 @@ ${render_galaxy_repository_actions( repository )}
install_dir = "This dependency's installation directory does not exist, click <b>Uninstall</b> to reset for installation."
%>
<tr>
<td>${tool_dependency.name}</td>
<td>${tool_dependency.version}</td>
<td>${tool_dependency.type}</td>
<td>${install_dir}</td>
<td>${tool_dependency.name|h}</td>
<td>${tool_dependency.version|h}</td>
<td>${tool_dependency.type|h}</td>
<td>${install_dir|h}</td>
</tr>
%endfor
</table>
@@ -11,7 +11,7 @@ ${render_galaxy_repository_actions( repository )}
%if tool_metadata:
<p/>
<div class="toolForm">
<div class="toolFormTitle">${tool_metadata[ 'name' ]} tool metadata</div>
<div class="toolFormTitle">${tool_metadata[ 'name' ]|h} tool metadata</div>
<div class="toolFormBody">
<div class="form-row">
<table width="100%">
@@ -20,41 +20,41 @@ ${render_galaxy_repository_actions( repository )}
</div>
<div class="form-row">
<label>Name:</label>
${tool_metadata[ 'name' ]}
${tool_metadata[ 'name' ]|h}
<div style="clear: both"></div>
</div>
%if 'description' in tool_metadata:
<div class="form-row">
<label>Description:</label>
${tool_metadata[ 'description' ]}
${tool_metadata[ 'description' ]|h}
<div style="clear: both"></div>
</div>
%endif
%if 'id' in tool_metadata:
<div class="form-row">
<label>Id:</label>
${tool_metadata[ 'id' ]}
${tool_metadata[ 'id' ]|h}
<div style="clear: both"></div>
</div>
%endif
%if 'guid' in tool_metadata:
<div class="form-row">
<label>Guid:</label>
${tool_metadata[ 'guid' ]}
${tool_metadata[ 'guid' ]|h}
<div style="clear: both"></div>
</div>
%endif
%if 'version' in tool_metadata:
<div class="form-row">
<label>Version:</label>
${tool_metadata[ 'version' ]}
${tool_metadata[ 'version' ]|h}
<div style="clear: both"></div>
</div>
%endif
%if 'version_string_cmd' in tool_metadata:
<div class="form-row">
<label>Version command string:</label>
${tool_metadata[ 'version_string_cmd' ]}
${tool_metadata[ 'version_string_cmd' ]|h}
<div style="clear: both"></div>
</div>
%endif
@@ -70,9 +70,9 @@ ${render_galaxy_repository_actions( repository )}
<tr>
<td>
%if guid == tool_metadata[ 'guid' ]:
${guid} <b>(this tool)</b>
${guid|h} <b>(this tool)</b>
%else:
${guid}
${guid|h}
%endif
</td>
</tr>
@@ -109,9 +109,9 @@ ${render_galaxy_repository_actions( repository )}
requirement_type = requirement_dict[ 'type' ] or 'not provided'
%>
<tr>
<td>${requirement_name}</td>
<td>${requirement_version}</td>
<td>${requirement_type}</td>
<td>${requirement_name|h}</td>
<td>${requirement_version|h}</td>
<td>${requirement_type|h}</td>
</tr>
%endfor
</table>
@@ -130,27 +130,27 @@ ${render_galaxy_repository_actions( repository )}
</div>
<div class="form-row">
<label>Command:</label>
<pre>${tool.command}</pre>
<pre>${tool.command|h}</pre>
<div style="clear: both"></div>
</div>
<div class="form-row">
<label>Interpreter:</label>
${tool.interpreter}
${tool.interpreter|h}
<div style="clear: both"></div>
</div>
<div class="form-row">
<label>Is multi-byte:</label>
${tool.is_multi_byte}
${tool.is_multi_byte|h}
<div style="clear: both"></div>
</div>
<div class="form-row">
<label>Forces a history refresh:</label>
${tool.force_history_refresh}
${tool.force_history_refresh|h}
<div style="clear: both"></div>
</div>
<div class="form-row">
<label>Parallelism:</label>
${tool.parallelism}
${tool.parallelism|h}
<div style="clear: both"></div>
</div>
%endif
@@ -181,20 +181,20 @@ ${render_galaxy_repository_actions( repository )}
required_files = test_dict[ 'required_files' ]
%>
<tr>
<td>${test_dict[ 'name' ]}</td>
<td>${test_dict[ 'name' ]|h}</td>
<td>
%for input in inputs:
<b>${input[0]}:</b> ${input[1]}<br/>
<b>${input[0]|h}:</b> ${input[1]|h}<br/>
%endfor
</td>
<td>
%for output in outputs:
<b>${output[0]}:</b> ${output[1]}<br/>
<b>${output[0]|h}:</b> ${output[1]|h}<br/>
%endfor
</td>
<td>
%for required_file in required_files:
${required_file}<br/>
${required_file|h}<br/>
%endfor
</td>
</tr>
@@ -17,7 +17,7 @@
<%def name="render_workflow( workflow_name, repository_id )">
<% center_url = h.url_for( controller='admin_toolshed', action='generate_workflow_image', workflow_name=tool_shed_encode( workflow_name ), repository_id=repository_id ) %>
<iframe name="workflow_image" id="workflow_image" frameborder="0" style="position: absolute; width: 100%; height: 100%;" src="${center_url}"> </iframe>
<iframe name="workflow_image" id="workflow_image" frameborder="0" style="position: absolute; width: 100%; height: 100%;" src="${center_url|h}"> </iframe>
</%def>
${render_galaxy_repository_actions( repository )}
+1 -1
View File
@@ -13,7 +13,7 @@
%for user in users:
<div class="form-row">
<label>Email:</label>
${user.email}
${user.email|h}
<div style="clear: both"></div>
</div>
%endfor
+7 -7
View File
@@ -11,9 +11,9 @@
</%def>
<%def name="render_select( name, options )">
<select name="${name}" id="${name}" style="min-width: 250px; height: 150px;" multiple>
<select name="${name|h}" id="${name|h}" style="min-width: 250px; height: 150px;" multiple>
%for option in options:
<option value="${option[0]}">${option[1]}</option>
<option value="${option[0]|h}">${option[1]|h}</option>
%endfor
</select>
</%def>
@@ -48,29 +48,29 @@ $().ready(function() {
%endif
<div class="toolForm">
<div class="toolFormTitle">User '${user.email}'</div>
<div class="toolFormTitle">User '${user.email|h}'</div>
<div class="toolFormBody">
<form name="associate_user_role_group" id="associate_user_role_group" action="${h.url_for(controller='admin', action='manage_roles_and_groups_for_user', id=trans.security.encode_id( user.id ) )}" method="post" >
<div class="form-row">
<div style="float: left; margin-right: 10px;">
<label>Roles associated with '${user.email}'</label>
<label>Roles associated with '${user.email|h}'</label>
${render_select( "in_roles", in_roles )}<br/>
<input type="submit" id="roles_remove_button" value=">>"/>
</div>
<div>
<label>Roles not associated with '${user.email}'</label>
<label>Roles not associated with '${user.email|h}'</label>
${render_select( "out_roles", out_roles )}<br/>
<input type="submit" id="roles_add_button" value="<<"/>
</div>
</div>
<div class="form-row">
<div style="float: left; margin-right: 10px;">
<label>Groups associated with '${user.email}'</label>
<label>Groups associated with '${user.email|h}'</label>
${render_select( "in_groups", in_groups )}<br/>
<input type="submit" id="groups_remove_button" value=">>"/>
</div>
<div>
<label>Groups not associated with '${user.email}'</label>
<label>Groups not associated with '${user.email|h}'</label>
${render_select( "out_groups", out_groups )}<br/>
<input type="submit" id="groups_add_button" value="<<"/>
</div>
+4 -4
View File
@@ -37,16 +37,16 @@
%else:
<tr class="tr">
%endif
<td>${datatype.extension}</td>
<td>${datatype.dtype}</td>
<td>${datatype.extension|h}</td>
<td>${datatype.dtype|h}</td>
<td>
%if datatype.mimetype:
${datatype.mimetype}
${datatype.mimetype|h}
%endif
</td>
<td>
%if datatype.display_in_upload:
${datatype.display_in_upload}
${datatype.display_in_upload|h}
%endif
</td>
</tr>
+1 -1
View File
@@ -39,7 +39,7 @@
<script>
Raven.config('${app.config.sentry_dsn_public}').install();
%if trans.user:
Raven.setUser( { email: "${trans.user.email}" } );
Raven.setUser( { email: "${trans.user.email|h}" } );
%endif
</script>
%endif
+2 -1
View File
@@ -70,11 +70,12 @@ ${ h.dumps( get_config_dict() )}
## Return a dictionary of user or anonymous user data including:
## email, id, disk space used, quota percent, and tags used
<%
from markupsafe import escape
user_dict = {}
try:
if trans.user:
user_dict = trans.user.to_dict( view='element',
value_mapper={ 'id': trans.security.encode_id, 'total_disk_usage': float } )
value_mapper={ 'id': trans.security.encode_id, 'total_disk_usage': float, 'email': escape, 'username': escape } )
user_dict[ 'quota_percent' ] = trans.app.quota_agent.get_percent( trans=trans )
user_dict[ 'is_admin' ] = trans.user_is_admin()
+1 -1
View File
@@ -2,7 +2,7 @@
%if trans.user:
<h2>${_('User preferences')}</h2>
<p>You are currently logged in as ${trans.user.email}.</p>
<p>You are currently logged in as ${trans.user.email|h}.</p>
<ul>
%if t.webapp.name == 'galaxy':
%if not trans.app.config.use_remote_user:
@@ -22,7 +22,7 @@
<tr class="libraryTitle">
<td>
<div style="float: left; margin-left: 1px;" class="menubutton split popup" id="dataset-${shed_id}-popup">
<a class="view-info" href="${h.url_for( controller='admin_toolshed', action='browse_tool_shed', tool_shed_url=url )}">${name}</a>
<a class="view-info" href="${h.url_for( controller='admin_toolshed', action='browse_tool_shed', tool_shed_url=url )}">${name|h}</a>
</div>
<div popupmenu="dataset-${shed_id}-popup">
<a class="action-button" href="${h.url_for( controller='admin_toolshed', action='browse_tool_shed', tool_shed_url=url )}">Browse valid repositories</a>
+1 -1
View File
@@ -95,7 +95,7 @@
<input type="hidden" name="id" value="${trans.security.encode_id( hda.id)}" />
<div class="form-row">
<label>Your email</label>
<input type="text" name="email" size="40" value="${user_email}" />
<input type="text" name="email" size="40" value="${user_email|h}" />
</div>
<div class="form-row">
<label>Message</label>
@@ -3,6 +3,7 @@
## masthead head generator
<%def name="load(active_view = None)">
<%
from markupsafe import escape
## get configuration
masthead_config = {
## inject configuration
@@ -32,7 +33,7 @@
## user details
'user' : {
'requests' : bool(trans.user and (trans.user.requests or trans.app.security_agent.get_accessible_request_types(trans, trans.user))),
'email' : trans.user.email if (trans.user) else "",
'email' : escape( trans.user.email ) if (trans.user) else "",
'valid' : bool(trans.user != None),
'json' : get_user_dict()
}
+1 -1
View File
@@ -49,7 +49,7 @@
<script>
Raven.config('${app.config.sentry_dsn_public}').install();
%if trans.user:
Raven.setUser( { email: "${trans.user.email}" } );
Raven.setUser( { email: "${trans.user.email|h}" } );
%endif
</script>
%endif
+3 -2
View File
@@ -91,7 +91,8 @@
%>
## User tabs.
<%
<%
from markupsafe import escape
# Menu for user who is not logged in.
menu_options = [ [ _("Login"), h.url_for( controller='/user', action='login' ), "galaxy_main" ] ]
if app.config.allow_user_creation:
@@ -101,7 +102,7 @@
tab( "user", _("User"), None, visible=visible, menu_options=menu_options )
# Menu for user who is logged in.
if trans.user:
email = trans.user.email
email = escape( trans.user.email )
else:
email = ""
menu_options = [ [ '<a>Logged in as <span id="user-email">%s</span></a>' % email ] ]