securedrop
securedrop copied to clipboard
Organization name gets escaped twice
Description
When configuring an instance's name as (for example) "Hello & World", the & shows up as & wherever the organization name is used, because it is escaped when it is being set and again when it is being displayed.
Comments
As far as I can tell, the organization name is the only user provided input that is escaped before it is set - oversight or intentional?
Probably more overzealousness!