Преглед изворни кода

sanitize UserGroup name when creating/updating with xss library

Yuki Takei пре 7 година
родитељ
комит
a6432518ce
1 измењених фајлова са 2 додато и 2 уклоњено
  1. 2 2
      lib/routes/admin.js

+ 2 - 2
lib/routes/admin.js

@@ -638,7 +638,7 @@ module.exports = function(crowi, app) {
   actions.userGroup.create = function(req, res) {
     const form = req.form.createGroupForm;
     if (req.form.isValid) {
-      const userGroupName = req.sanitize(form.userGroupName);
+      const userGroupName = crowi.xss.process(form.userGroupName);
 
       UserGroup.createGroupByName(userGroupName)
         .then((newUserGroup) => {
@@ -661,7 +661,7 @@ module.exports = function(crowi, app) {
   actions.userGroup.update = function(req, res) {
 
     const userGroupId = req.params.userGroupId;
-    const name = req.sanitize(req.body.name);
+    const name = crowi.xss.process(req.body.name);
 
     UserGroup.findById(userGroupId)
     .then((userGroupData) => {