Bläddra i källkod

fileboard: fix possible XSS (mainly applicable to 8chan)

pull/18/head
czaks 9 år sedan
förälder
incheckning
271dcb7a65
2 ändrade filer med 2 tillägg och 2 borttagningar
  1. +1
    -1
      templates/post_form.html
  2. +1
    -1
      templates/post_thread_fileboard.html

+ 1
- 1
templates/post_form.html Visa fil

@@ -98,7 +98,7 @@
<td>
<select name="tag">
{% for id, tag in config.allowed_tags %}
<option value="{{ id }}">{{ tag }}</option>
<option value="{{ id|e }}">{{ tag|e }}</option>
{% endfor %}
</select>
</td>


+ 1
- 1
templates/post_thread_fileboard.html Visa fil

@@ -9,7 +9,7 @@
<td>{% include 'post/name.html' %}
{% include 'post/flag.html' %}
<td>[<a href="{{ config.uri_img }}{{ post.files[0].file }}">{{ post.files[0].filename|e|bidi_cleanup }}</a>]
<td>{% if post.modifiers['tag'] %}[{{ post.modifiers['tag'] }}]{% endif %}
<td>{% if post.modifiers['tag'] %}[{{ post.modifiers['tag']|e }}]{% endif %}
<td>{% include 'post/subject.html' %}
{% if post.sticky %}
{% if config.font_awesome %}


Laddar…
Avbryt
Spara