Sfoglia il codice sorgente

Merge pull request #1549 from brun0ne/fix-xss

Fixed xss in addOperation
a3957273 1 anno fa
parent
commit
75c4e196fa
1 ha cambiato i file con 5 aggiunte e 1 eliminazioni
  1. 5 1
      src/web/waiters/RecipeWaiter.mjs

+ 5 - 1
src/web/waiters/RecipeWaiter.mjs

@@ -396,7 +396,11 @@ class RecipeWaiter {
         const item = document.createElement("li");
 
         item.classList.add("operation");
-        item.innerHTML = name;
+
+        if (this.app.operations[name] != null) {
+            item.innerHTML = name;
+        }
+
         this.buildRecipeOperation(item);
         document.getElementById("rec-list").appendChild(item);