Merge pull request #463 from korpd/fix-xss-parameter-style
Fix reflected XSS in 'style' parameter
This commit is contained in:
commit
042b8b986a
1 changed files with 1 additions and 1 deletions
|
@ -43,7 +43,7 @@ module.exports.getTileUrls = (req, domains, path, format, publicUrl, aliases) =>
|
||||||
queryParams.push(`key=${encodeURIComponent(req.query.key)}`);
|
queryParams.push(`key=${encodeURIComponent(req.query.key)}`);
|
||||||
}
|
}
|
||||||
if (req.query.style) {
|
if (req.query.style) {
|
||||||
queryParams.push(`style=${req.query.style}`);
|
queryParams.push(`style=${encodeURIComponent(req.query.style)}`);
|
||||||
}
|
}
|
||||||
const query = queryParams.length > 0 ? (`?${queryParams.join('&')}`) : '';
|
const query = queryParams.length > 0 ? (`?${queryParams.join('&')}`) : '';
|
||||||
|
|
||||||
|
|
Loading…
Reference in a new issue