Skip to content

Commit 1a5df9e

Browse files
appleboylunny
authored andcommitted
Security: fix XSS attack on alert (#981)
1 parent 21dc599 commit 1a5df9e

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

templates/base/alert.tmpl

+3-3
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,15 @@
11
{{if .Flash.ErrorMsg}}
22
<div class="ui negative message">
3-
<p>{{.Flash.ErrorMsg | Safe}}</p>
3+
<p>{{.Flash.ErrorMsg | Str2html}}</p>
44
</div>
55
{{end}}
66
{{if .Flash.SuccessMsg}}
77
<div class="ui positive message">
8-
<p>{{.Flash.SuccessMsg | Safe}}</p>
8+
<p>{{.Flash.SuccessMsg | Str2html}}</p>
99
</div>
1010
{{end}}
1111
{{if .Flash.InfoMsg}}
1212
<div class="ui info message">
13-
<p>{{.Flash.InfoMsg | Safe}}</p>
13+
<p>{{.Flash.InfoMsg | Str2html}}</p>
1414
</div>
1515
{{end}}

0 commit comments

Comments
 (0)