Template gameName into player-settings as a data attribute to avoid potential security risks.

This commit is contained in:
Chris Wilson
2021-07-25 15:49:51 -04:00
parent 35b9e4768a
commit 610871c61b
3 changed files with 4 additions and 5 deletions

View File

@@ -106,7 +106,7 @@ games_list = {
# Player settings pages
@app.route('/games/<string:game>/player-settings')
def player_settings(game):
return render_template(f"player-settings.html")
return render_template(f"player-settings.html", game=game)
# Game sub-pages