fixed xss issue with mentions

This commit is contained in:
supertiger1234 2020-02-28 21:44:55 +00:00
parent 6599160707
commit 980d778504

View file

@ -17,10 +17,14 @@ export default order => {
html: function(node) {
const member = store.getters["members/members"][node.id];
if (!member) return node.orig;
return SimpleMarkdown.htmlTag("span", "@" + member.username, {
class: "mention",
id: "mention-" + member.uniqueID
});
return SimpleMarkdown.htmlTag(
"span",
"@" + SimpleMarkdown.sanitizeText(member.username),
{
class: "mention",
id: "mention-" + member.uniqueID
}
);
}
};
};