mirror of
https://github.com/ansible/awx.git
synced 2024-11-01 08:21:15 +03:00
Merge pull request #149 from mabashian/7283-xss-schedules
Sanitize schedule titles
This commit is contained in:
commit
77f4e21e19
@ -85,9 +85,9 @@ export default
|
|||||||
},
|
},
|
||||||
views: {
|
views: {
|
||||||
'@': {
|
'@': {
|
||||||
templateProvider: function(ScheduleList, generateList, ParentObject){
|
templateProvider: function(ScheduleList, generateList, ParentObject, $filter){
|
||||||
// include name of parent resource in listTitle
|
// include name of parent resource in listTitle
|
||||||
ScheduleList.listTitle = `${ParentObject.name}<div class='List-titleLockup'></div>` + N_('SCHEDULES');
|
ScheduleList.listTitle = `${$filter('sanitize')(ParentObject.name)}<div class='List-titleLockup'></div>` + N_('SCHEDULES');
|
||||||
let html = generateList.build({
|
let html = generateList.build({
|
||||||
list: ScheduleList,
|
list: ScheduleList,
|
||||||
mode: 'edit'
|
mode: 'edit'
|
||||||
@ -178,9 +178,9 @@ export default
|
|||||||
},
|
},
|
||||||
views: {
|
views: {
|
||||||
'@': {
|
'@': {
|
||||||
templateProvider: function(ScheduleList, generateList, ParentObject){
|
templateProvider: function(ScheduleList, generateList, ParentObject, $filter){
|
||||||
// include name of parent resource in listTitle
|
// include name of parent resource in listTitle
|
||||||
ScheduleList.listTitle = `${ParentObject.name}<div class='List-titleLockup'></div>` + N_('SCHEDULES');
|
ScheduleList.listTitle = `${$filter('sanitize')(ParentObject.name)}<div class='List-titleLockup'></div>` + N_('SCHEDULES');
|
||||||
let html = generateList.build({
|
let html = generateList.build({
|
||||||
list: ScheduleList,
|
list: ScheduleList,
|
||||||
mode: 'edit'
|
mode: 'edit'
|
||||||
@ -268,9 +268,9 @@ export default
|
|||||||
},
|
},
|
||||||
views: {
|
views: {
|
||||||
'@': {
|
'@': {
|
||||||
templateProvider: function(ScheduleList, generateList, ParentObject){
|
templateProvider: function(ScheduleList, generateList, ParentObject, $filter){
|
||||||
// include name of parent resource in listTitle
|
// include name of parent resource in listTitle
|
||||||
ScheduleList.listTitle = `${ParentObject.name}<div class='List-titleLockup'></div>` + N_('SCHEDULES');
|
ScheduleList.listTitle = `${$filter('sanitize')(ParentObject.name)}<div class='List-titleLockup'></div>` + N_('SCHEDULES');
|
||||||
let html = generateList.build({
|
let html = generateList.build({
|
||||||
list: ScheduleList,
|
list: ScheduleList,
|
||||||
mode: 'edit'
|
mode: 'edit'
|
||||||
|
Loading…
Reference in New Issue
Block a user