Przeglądaj źródła

use preventXss for page_alerts

Yuki Takei 5 lat temu
rodzic
commit
22e2e4a967
1 zmienionych plików z 2 dodań i 2 usunięć
  1. 2 2
      src/server/views/widget/page_alerts.html

+ 2 - 2
src/server/views/widget/page_alerts.html

@@ -33,10 +33,10 @@
       <span>
         {% set fromPath = req.query.renamed or req.query.redirectFrom %}
         {% if redirectFrom or req.query.redirectFrom %}
-          <strong>{{ t('Redirected') }}:</strong> {{ t('page_page.notice.redirected', req.sanitize(fromPath)) }}
+          <strong>{{ t('Redirected') }}:</strong> {{ t('page_page.notice.redirected', fromPath | preventXss) }}
         {% endif %}
         {% if req.query.renamed %}
-          <strong>{{ t('Moved') }}:</strong> {{ t('page_page.notice.moved', req.sanitize(fromPath)) }}
+          <strong>{{ t('Moved') }}:</strong> {{ t('page_page.notice.moved', fromPath | preventXss) }}
         {% endif %}
       </span>
       {% if user and not page.isDeleted() %}