{% extends "base.html" %} {% block title %}{{ peer.name }} — BBS Directory{% endblock %} {% block content %}
Back to Directory

{{ peer.name }}

{% if peer.location %}

{{ peer.location }}

{% endif %} {% if peer.description %}

{{ peer.description }}

{% endif %}
Telnet
{{ peer.hostname }}{% if peer.telnet_port and peer.telnet_port != 23 %}:{{ peer.telnet_port }}{% endif %}
{% if peer.web_url %} {# Security fix (templates audit): web_url is submitted by any logged-in user via peers.submit (self-service directory listing, pending sysop approval) with no scheme validation on save (web/peers.py). A javascript: URI here would execute in a viewer's session -- including the sysop's own session while reviewing the pending submission for approval. Only link-ify actual http(s) URLs. #} {% set _web = peer.web_url.strip() %} {% set _web_safe = _web.lower().startswith('http://') or _web.lower().startswith('https://') %}
Web
{% if _web_safe %}{{ _web }}{% else %}{{ _web }}{% endif %}
{% endif %} {% if peer.software %}
Software
{{ peer.software }}
{% endif %} {% if peer.ftn_address %}
FTN Address
{{ peer.ftn_address }}
{% endif %}
Connect via Telnet {% if peer.web_url and _web_safe %} Visit Web {% endif %} {% if peer.ftn_address %} Send Telegram {% endif %}
{% endblock %}