Index: openacs-4/packages/xowiki/tcl/syndicate-procs.tcl =================================================================== RCS file: /usr/local/cvsroot/openacs-4/packages/xowiki/tcl/syndicate-procs.tcl,v diff -u -r1.51 -r1.51.2.1 --- openacs-4/packages/xowiki/tcl/syndicate-procs.tcl 9 Apr 2018 07:58:06 -0000 1.51 +++ openacs-4/packages/xowiki/tcl/syndicate-procs.tcl 6 Mar 2019 17:51:34 -0000 1.51.2.1 @@ -24,7 +24,7 @@ Class create RSS -superclass XMLSyndication -parameter { maxentries - {parent_ids ""} + {parent_ids:integer,0..n ""} {name_filter ""} {entries_of ""} {days ""} Index: openacs-4/packages/xowiki/tcl/weblog-procs.tcl =================================================================== RCS file: /usr/local/cvsroot/openacs-4/packages/xowiki/tcl/weblog-procs.tcl,v diff -u -r1.75.2.1 -r1.75.2.2 --- openacs-4/packages/xowiki/tcl/weblog-procs.tcl 6 Mar 2019 16:57:18 -0000 1.75.2.1 +++ openacs-4/packages/xowiki/tcl/weblog-procs.tcl 6 Mar 2019 17:51:34 -0000 1.75.2.2 @@ -35,6 +35,9 @@ } { set form_item_ids [list] foreach t [split $forms |] { + if {![regexp {^[[:alnum:]:._]+$} $t]} { + error "invalid form specificaton '$t'" + } #:log "trying to get $t // parent_id $parent_id" set page [$package_id get_page_from_item_ref \ -use_prototype_pages true \