diff --git a/lib/galaxy/tools/toolbox/integrated_panel.py b/lib/galaxy/tools/toolbox/integrated_panel.py index c17d9c8387b..e744064e6bf 100644 --- a/lib/galaxy/tools/toolbox/integrated_panel.py +++ b/lib/galaxy/tools/toolbox/integrated_panel.py @@ -3,6 +3,7 @@ import shutil import tempfile import time import traceback +from xml.sax.saxutils import escape from .panel import ToolPanelElements from .panel import panel_item_types @@ -78,7 +79,7 @@ class ManagesIntegratedToolPanelMixin: section_id = item.id or '' section_name = item.name or '' section_version = item.version or '' - os.write( fd, '
\n' % ( section_id, section_name, section_version ) ) + os.write( fd, '
\n' % ( escape(section_id), escape(section_name), section_version ) ) for section_key, section_item_type, section_item in item.panel_items_iter(): if section_item_type == panel_item_types.TOOL: if section_item: diff --git a/lib/galaxy/util/__init__.py b/lib/galaxy/util/__init__.py index e55cd8cbb87..04b705c462e 100644 --- a/lib/galaxy/util/__init__.py +++ b/lib/galaxy/util/__init__.py @@ -45,6 +45,10 @@ except ImportError: docutils_html4css1 = None from xml.etree import ElementTree, ElementInclude +try: + from xml.etree.ElementTree import ParseError +except ImportError: + from xml.parsers.expat import ExpatError as ParseError from .inflection import Inflector, English inflector = Inflector(English) @@ -184,7 +188,11 @@ def parse_xml( fname ): def doctype( *args ): pass tree = ElementTree.ElementTree() - root = tree.parse( fname, parser=ElementTree.XMLParser( target=DoctypeSafeCallbackTarget() ) ) + try: + root = tree.parse( fname, parser=ElementTree.XMLParser( target=DoctypeSafeCallbackTarget() ) ) + except ParseError: + log.exception("Error parsing file %s", fname) + raise ElementInclude.include( root ) return tree