fixing html sanitiation
This commit is contained in:
parent
bc4a8d60f4
commit
fd2c6fd49e
3 changed files with 6 additions and 4 deletions
|
@ -30,11 +30,11 @@ module.exports = Mn.View.extend({
|
||||||
},
|
},
|
||||||
createSpecificTableCell: function(value) {
|
createSpecificTableCell: function(value) {
|
||||||
if (value && value.trim() !== '') {
|
if (value && value.trim() !== '') {
|
||||||
|
value = value.replace(/&/g, "&").replace(/</g, "<").replace(/>/g, ">").replace(/"/g, """).replace(/'/g, "'");
|
||||||
return `<td>${value}</td>`;
|
return `<td>${value}</td>`;
|
||||||
} else {
|
} else {
|
||||||
return `<td class="text-center">-</td>`;
|
return `<td class="text-center">-</td>`;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
|
@ -30,6 +30,7 @@ module.exports = Mn.View.extend({
|
||||||
},
|
},
|
||||||
createSpecificTableCell: function(value) {
|
createSpecificTableCell: function(value) {
|
||||||
if (value && value.trim() !== '') {
|
if (value && value.trim() !== '') {
|
||||||
|
value = value.replace(/&/g, "&").replace(/</g, "<").replace(/>/g, ">").replace(/"/g, """).replace(/'/g, "'");
|
||||||
return `<td>${value}</td>`;
|
return `<td>${value}</td>`;
|
||||||
} else {
|
} else {
|
||||||
return `<td class="text-center">-</td>`;
|
return `<td class="text-center">-</td>`;
|
||||||
|
|
|
@ -30,6 +30,7 @@ module.exports = Mn.View.extend({
|
||||||
},
|
},
|
||||||
createSpecificTableCell: function(value) {
|
createSpecificTableCell: function(value) {
|
||||||
if (value && value.trim() !== '') {
|
if (value && value.trim() !== '') {
|
||||||
|
value = value.replace(/&/g, "&").replace(/</g, "<").replace(/>/g, ">").replace(/"/g, """).replace(/'/g, "'");
|
||||||
return `<td>${value}</td>`;
|
return `<td>${value}</td>`;
|
||||||
} else {
|
} else {
|
||||||
return `<td class="text-center">-</td>`;
|
return `<td class="text-center">-</td>`;
|
||||||
|
|
Loading…
Reference in a new issue