Skip to content

Commit

Permalink
Bug no. 32 - XSS zranitelnost viz Wiki
Browse files Browse the repository at this point in the history
  • Loading branch information
arxeiss committed Mar 4, 2024
1 parent 2665d0a commit 543bfd6
Show file tree
Hide file tree
Showing 3 changed files with 14 additions and 14 deletions.
24 changes: 12 additions & 12 deletions resources/assets/js/partials/app.js
Original file line number Diff line number Diff line change
Expand Up @@ -226,18 +226,18 @@ export default {
}
}

if (this.dtConfig.columns) {
var targets = [];
for (var i = 0; i < this.dtConfig.columns.length; i++) {
targets.push(i)
}

if (this.dtConfig.columnDefs) {
this.dtConfig.columnDefs.push({targets:targets, render: this.preventXSSRenderer});
}else{
this.dtConfig.columnDefs = [{targets:targets, render: this.preventXSSRenderer}];
}
}
// if (this.dtConfig.columns) {
// var targets = [];
// for (var i = 0; i < this.dtConfig.columns.length; i++) {
// targets.push(i)
// }

// if (this.dtConfig.columnDefs) {
// this.dtConfig.columnDefs.push({targets:targets, render: this.preventXSSRenderer});
// }else{
// this.dtConfig.columnDefs = [{targets:targets, render: this.preventXSSRenderer}];
// }
// }

// Init DataTable
this.instance = $tableEl.DataTable(
Expand Down
2 changes: 1 addition & 1 deletion resources/views/admin/users/delete.blade.php
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@
</p>

@component('components.modal_yes_no_form', [ 'id' => 'deleteUser', 'route' => route('admin.users.destroy', $user)] )
@lang('users.delete_modal', ['name' => e($user->name)])
@lang('users.delete_modal', ['name' => $user->name])
@endcomponent
@else
<h4>@lang('users.delete.cannot')</h4>
Expand Down
2 changes: 1 addition & 1 deletion resources/views/admin/users/show.blade.php
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@
@endcan
@can('delete', $user)
@component('components.modal_yes_no_form', [ 'id' => 'deleteUser', 'route' => route('admin.users.destroy', $user)] )
@lang('users.delete_modal', ['name' => str_replace(" ", "&nbsp;", e($user->name))])
@lang('users.delete_modal', ['name' => str_replace(" ", "&nbsp;", $user->name)])
@endcomponent
<a href="#deleteUser" data-toggle="modal" class="btn btn-sm btn-danger">
<i class="fa fa-fw fa-trash"></i>
Expand Down

0 comments on commit 543bfd6

Please sign in to comment.