|
|
@@ -230,6 +230,10 @@ module.exports = function(crowi, app) {
|
|
|
}
|
|
|
|
|
|
function addRenderVarsForPresentation(renderVars, page) {
|
|
|
+
|
|
|
+ const preventXssRevision = page.revision.body.replace(/</g, '<').replace(/>/g, '>');
|
|
|
+ page.revision.body = preventXssRevision;
|
|
|
+
|
|
|
renderVars.page = page;
|
|
|
renderVars.revision = page.revision;
|
|
|
}
|