Skip to content

Commit 09be5ac

Browse files
committed
Fix possible xss bug
1 parent 0be30d9 commit 09be5ac

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

templates/repo/issue/view_content/comments.tmpl

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -619,12 +619,12 @@
619619
{{template "shared/user/avatarlink" dict "user" .Poster}}
620620
<span class="text grey muted-links">
621621
{{template "shared/user/authorlink" .Poster}}
622-
{{$newProjectDisplayHtml := .CommentMetaData.ProjectTitle|Safe}}
622+
{{$newProjectDisplayHtml := .CommentMetaData.ProjectTitle}}
623623
{{if .Project}}
624624
{{$trKey := printf "projects.type-%d.display_name" .Project.Type}}
625625
{{$newProjectDisplayHtml = printf `%s <a href="%s"><span data-tooltip-content="%s">%s</span></a>` (svg .Project.IconName) (.Project.Link ctx) (ctx.Locale.Tr $trKey | Escape) (.Project.Title | Escape)}}
626626
{{end}}
627-
{{ctx.Locale.Tr "repo.issues.move_to_column_of_project" (.CommentMetaData.ProjectColumnTitle|Safe) ($newProjectDisplayHtml|Safe) $createdStr}}
627+
{{ctx.Locale.Tr "repo.issues.move_to_column_of_project" (.CommentMetaData.ProjectColumnTitle|Escape) ($newProjectDisplayHtml|Safe) $createdStr}}
628628
</span>
629629
</div>
630630
{{end}}

0 commit comments

Comments
 (0)