From 78c17773db1c6f501221a4f3e6114af6fbed0f19 Mon Sep 17 00:00:00 2001 From: Michael Nutt Date: Thu, 19 Jan 2023 00:12:31 -0500 Subject: [PATCH] Fix xss due to handlebars variables in javascript (#535) * fix xss due to handlebars variables in javascript * fix: update data viewer against XSS Signed-off-by: Michael Nutt * fix: remove key_query from all static assets to prevent XSS Signed-off-by: Michael Nutt Signed-off-by: Michael Nutt --- public/templates/data.tmpl | 26 ++++++++++++++++---------- public/templates/index.tmpl | 4 ++-- public/templates/viewer.tmpl | 26 +++++++++++++++----------- 3 files changed, 33 insertions(+), 23 deletions(-) diff --git a/public/templates/data.tmpl b/public/templates/data.tmpl index db51c2c..203c45c 100644 --- a/public/templates/data.tmpl +++ b/public/templates/data.tmpl @@ -5,10 +5,10 @@ {{name}} - TileServer GL {{#is_vector}} - - - - + + + + {{/is_vector}} {{^is_vector}} - - - - + + + +