Properly escape HTML

main
Pk11 3 years ago
parent b629d4ee17
commit 2f4e9f3892

@ -9,7 +9,7 @@
<meta property="og:url" content="https://home.pk11.us/video.php">
<meta property="title" content="Discord video embedder">
<?php $video = str_replace(' ', '%20', $_GET['video']); ?>
<?php $video = htmlspecialchars(str_replace(' ', '%20', $_GET['video'])); ?>
<?php if($video) { ?>
<meta property="og:video" content="<?php echo $video ?>">
@ -43,7 +43,7 @@
<body>
<?php if($video) { ?>
<video controls autoplay>
<source src="<?php echo $video ?>" type="video/mp4">
<source src="<?php echo $video; ?>" type="video/mp4">
</video>
<?php } else { ?>
<p>Put ?video=[link to video] at the end of the URL and Discord will show an embed of that video.</p>

Loading…
Cancel
Save