Skip to content

Commit

Permalink
fix(docs): fix doc editing xss
Browse files Browse the repository at this point in the history
  • Loading branch information
mrilyew committed Jan 22, 2025
1 parent 9177075 commit 67653c7
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions Web/static/js/al_docs.js
Original file line number Diff line number Diff line change
Expand Up @@ -131,7 +131,7 @@ u(document).on('click', '.docMainItem #edit_icon', async (e) => {
title: tr("document_editing_in_general"),
body: `
<p><b>${tr("info_name")}</b></p>
<input maxlength="128" type="text" name="doc_name" value="${doc.title}" placeholder="...">
<input maxlength="128" type="text" name="doc_name" value="${escapeHtml(doc.title)}" placeholder="...">
<label>
<input value="0" type="radio" name="doc_access" ${doc.folder_id != 3 ? "checked" : ''}>
Expand All @@ -144,7 +144,7 @@ u(document).on('click', '.docMainItem #edit_icon', async (e) => {
</label>
<p><b>${tr("tags")}</b></p>
<input maxlength="256" type="text" name="doc_tags" value="${doc.tags.join(',')}" placeholder="...">
<input maxlength="256" type="text" name="doc_tags" value="${escapeHtml(doc.tags.join(','))}" placeholder="...">
<br>
<label>
<input type="checkbox" name="doc_owner" ${doc.is_hidden ? "checked" : ''}>
Expand Down

0 comments on commit 67653c7

Please sign in to comment.