zamis 5 years ago
parent
commit
49fa9d8e52
1 changed files with 8 additions and 2 deletions
  1. 8 2
      src/server/routes/page.js

+ 8 - 2
src/server/routes/page.js

@@ -230,8 +230,14 @@ module.exports = function(crowi, app) {
   }
 
   function addRenderVarsForPresentation(renderVars, page) {
-
-    const preventXssRevision = page.revision.body.replace(/</g, '&lt;').replace(/>/g, '&gt;');
+    // const XssService = require('../service/xss');
+    // const preventXssRevision = new XssService();
+    // const hoge = preventXssRevision.process(page.revision.body);
+    // console.log(hoge);
+    // page.revision.body = hoge;
+
+    // sanitize revision.body
+    const preventXssRevision = crowi.xss.process(page.revision.body);
     page.revision.body = preventXssRevision;
 
     renderVars.page = page;