Merge pull request #2158 from anoek/2148

Fixed XSS for project and jt scheduling
This commit is contained in:
Akita Noek 2016-06-03 16:06:19 -04:00
commit 0a5b2aea0a

View File

@ -55,8 +55,8 @@ export default [
schedList.well = true;
// include name of item in listTitle
schedList.listTitle = title ? title : parentObject.name;
schedList.listTitle = `${schedList.listTitle}<div class='List-titleLockup'></div>Schedules`;
let escaped_title = $("<span>").text(title ? title : parentObject.name)[0].innerHTML;
schedList.listTitle = `${escaped_title}<div class='List-titleLockup'></div>Schedules`;
schedList.basePath = parentObject.url + "schedules";