mirror of
https://github.com/ansible/awx.git
synced 2026-01-22 23:18:03 -03:30
Merge pull request #2351 from mabashian/2301-xss
Rolls back changes to the xss filter. Addresses escaped characters in cred tags.
This commit is contained in:
commit
1c194dbfbc
@ -417,7 +417,7 @@ function buildCredentialDetails (credential) {
|
||||
const icon = `${credential.kind}`;
|
||||
const link = `/#/credentials/${credential.id}`;
|
||||
const tooltip = strings.get('tooltips.CREDENTIAL');
|
||||
const value = $filter('sanitize')(credential.name);
|
||||
const value = credential.name;
|
||||
|
||||
return { icon, link, tooltip, value };
|
||||
}
|
||||
|
||||
@ -170,10 +170,10 @@ function ListTemplatesController(
|
||||
const icon = `${credential.kind}`;
|
||||
const link = `/#/credentials/${credential.id}`;
|
||||
const tooltip = strings.get('tooltips.VIEW_THE_CREDENTIAL');
|
||||
const value = $filter('sanitize')(credential.name);
|
||||
const value = credential.name;
|
||||
|
||||
return { icon, link, tooltip, value };
|
||||
})
|
||||
});
|
||||
};
|
||||
|
||||
vm.getLastRan = template => {
|
||||
|
||||
@ -6,7 +6,7 @@
|
||||
|
||||
export default [function() {
|
||||
return function(input) {
|
||||
input = $("<span>").text(input)[0].textContent;
|
||||
input = $("<span>").text(input)[0].innerHTML;
|
||||
return input;
|
||||
};
|
||||
}];
|
||||
|
||||
@ -12,6 +12,6 @@ describe('Filter: sanitize', () => {
|
||||
});
|
||||
|
||||
it('should sanitize xss-vulnerable strings', function(){
|
||||
expect(filter("<div>foobar</div>")).toBe("<div>foobar</div>");
|
||||
expect(filter("<div>foobar</div>")).toBe("<div>foobar</div>");
|
||||
});
|
||||
});
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user