diff --git a/Website/__init__.py b/Website/__init__.py index fce7d9f..059668a 100644 --- a/Website/__init__.py +++ b/Website/__init__.py @@ -64,7 +64,7 @@ def create_app(test_config=None): c = db.cursor() c.execute("SELECT * FROM users") users = c.fetchall() - return render_template("list.html", users=escape(users), preis=escape(preis/100)) + return render_template("list.html", user_name=users preis=(preis/100) @app.route("/transactionlist") def transactionlist(): @@ -124,7 +124,7 @@ def create_app(test_config=None): if user != None : c.execute(f"SELECT * FROM tags WHERE userid={user[0]}") tags = c.fetchall() - return render_template("user.html", user=escape(user), tags=escape(tags)) + return render_template("user.html", user=user, tags=tags) else: return render_template("error.html", error_code="043") @@ -144,7 +144,7 @@ def create_app(test_config=None): user_name = user[1] db.remove_user(user_id) socketio.emit("update", "update") - return render_template("removeuser.html", user_name=escape(user_name)) + return render_template("removeuser.html", user_name=user_name) else: return render_template("error.html", error_code="043") @@ -235,7 +235,7 @@ def create_app(test_config=None): session_id = uuid.uuid4() session[id] = session_id user_queue.put([user_id, "remove", session_id]) - return render_template("removetag.html", user=escape(user_id)) + return render_template("removetag.html", user=user_id) else: db = get_db() c = db.cursor()