cgi.escape is just this:
def escape(s, quote=None):
'''Replace special characters "&", "<" and ">" to HTML-safe sequences.
If the optional flag quote is true, the quotation mark character (")
is also translated.'''
s = s.replace("&", "&") # Must be done first!
s = s.replace("<", "<")
s = s.replace(">", ">")
if quote:
s = s.replace('"', """)
return s
And the author would simplify the job as you point out by escaping the git log output first, then wrapping it in HTML. You don't even need the null byte. %H is a hex sequence, so even a space separator would be fine. This would do:
git log --pretty='%H %s' |
sed -e '
s/&/\&/g; # must be done first
s/</\</g;
s/>/\>/g;
s/^\([0-9a-f][0-9a-f]*\) \(.*\)/<tr><td>\1<\/td><td>\2<\/td><\/tr>/'
That said: it's best not to be cavalier about dealing with user input. This is sufficient only if the output is going into the body of the HTML document. You have to be careful about where the output is being placed:
https://www.owasp.org/index.php/XSS_%28Cross_Site_Scripting%...