mirror of
https://github.com/ansible/awx.git
synced 2026-05-07 01:17:37 -02:30
Merge pull request #31 from mabashian/7281-xss-inv-source
Fix inv source schedule title sanitizing
This commit is contained in:
@@ -44,9 +44,9 @@ export default {
|
|||||||
},
|
},
|
||||||
// target the un-named ui-view @ root level
|
// target the un-named ui-view @ root level
|
||||||
'@': {
|
'@': {
|
||||||
templateProvider: function(ScheduleList, generateList, ParentObject) {
|
templateProvider: function(ScheduleList, generateList, ParentObject, $filter) {
|
||||||
// include name of parent resource in listTitle
|
// include name of parent resource in listTitle
|
||||||
ScheduleList.listTitle = `${ParentObject.name}<div class='List-titleLockup'></div>` + N_('SCHEDULES');
|
ScheduleList.listTitle = `${$filter('sanitize')(ParentObject.name)}<div class='List-titleLockup'></div>` + N_('SCHEDULES');
|
||||||
let html = generateList.build({
|
let html = generateList.build({
|
||||||
list: ScheduleList,
|
list: ScheduleList,
|
||||||
mode: 'edit'
|
mode: 'edit'
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ export default ['i18n', function(i18n) {
|
|||||||
iterator: 'schedule',
|
iterator: 'schedule',
|
||||||
selectTitle: '',
|
selectTitle: '',
|
||||||
editTitle: 'SCHEDULES',
|
editTitle: 'SCHEDULES',
|
||||||
listTitle: '{{parentObject}} || SCHEDULES',
|
listTitle: '{{parentObject | sanitize}} || SCHEDULES',
|
||||||
index: false,
|
index: false,
|
||||||
hover: true,
|
hover: true,
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user