mirror of
https://github.com/Part-DB/Part-DB-server.git
synced 2025-06-28 20:50:06 +02:00
Properly escape user provided data in trans with data to prevent possible XSS attack vectors.
This commit is contained in:
parent
6ff60e556e
commit
5f39d8e594
3 changed files with 3 additions and 3 deletions
|
@ -67,7 +67,7 @@ class PartDataTableHelper
|
||||||
'<a href="%s">%s%s</a>',
|
'<a href="%s">%s%s</a>',
|
||||||
$this->entityURLGenerator->infoURL($context),
|
$this->entityURLGenerator->infoURL($context),
|
||||||
$icon,
|
$icon,
|
||||||
htmlentities($context->getName())
|
htmlspecialchars($context->getName())
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
@ -1,5 +1,5 @@
|
||||||
<form method="post" class="" action="{{ entity_url(entity, 'delete') }}" {{ stimulus_controller('elements/delete_btn') }} {{ stimulus_action('elements/delete_btn', "submit", "submit") }}
|
<form method="post" class="" action="{{ entity_url(entity, 'delete') }}" {{ stimulus_controller('elements/delete_btn') }} {{ stimulus_action('elements/delete_btn', "submit", "submit") }}
|
||||||
data-delete-title="{% trans with {'%name%': entity.name }%}entity.delete.confirm_title{% endtrans %}"
|
data-delete-title="{% trans with {'%name%': entity.name|escape }%}entity.delete.confirm_title{% endtrans %}"
|
||||||
data-delete-message="{% trans %}entity.delete.message{% endtrans %}">
|
data-delete-message="{% trans %}entity.delete.message{% endtrans %}">
|
||||||
<input type="hidden" name="_method" value="DELETE">
|
<input type="hidden" name="_method" value="DELETE">
|
||||||
<input type="hidden" name="_token" value="{{ csrf_token('delete' ~ entity.id) }}">
|
<input type="hidden" name="_token" value="{{ csrf_token('delete' ~ entity.id) }}">
|
||||||
|
|
|
@ -29,7 +29,7 @@
|
||||||
|
|
||||||
<form method="post" class="mt-2" action="{{ entity_url(part, 'delete') }}"
|
<form method="post" class="mt-2" action="{{ entity_url(part, 'delete') }}"
|
||||||
{{ stimulus_controller('elements/delete_btn') }} {{ stimulus_action('elements/delete_btn', "submit", "submit") }}
|
{{ stimulus_controller('elements/delete_btn') }} {{ stimulus_action('elements/delete_btn', "submit", "submit") }}
|
||||||
data-delete-title="{% trans with {'%name%': part.name }%}part.delete.confirm_title{% endtrans %}"
|
data-delete-title="{% trans with {'%name%': part.name|escape }%}part.delete.confirm_title{% endtrans %}"
|
||||||
data-delete-message="{% trans %}part.delete.message{% endtrans %}">
|
data-delete-message="{% trans %}part.delete.message{% endtrans %}">
|
||||||
<input type="hidden" name="_method" value="DELETE">
|
<input type="hidden" name="_method" value="DELETE">
|
||||||
<input type="hidden" name="_token" value="{{ csrf_token('delete' ~ part.id) }}">
|
<input type="hidden" name="_token" value="{{ csrf_token('delete' ~ part.id) }}">
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue