Explorar o código

Merge pull request #1549 from brun0ne/fix-xss

Fixed xss in addOperation
a3957273 hai 1 ano
pai
achega
75c4e196fa
Modificáronse 1 ficheiros con 5 adicións e 1 borrados
  1. 5 1
      src/web/waiters/RecipeWaiter.mjs

+ 5 - 1
src/web/waiters/RecipeWaiter.mjs

@@ -396,7 +396,11 @@ class RecipeWaiter {
         const item = document.createElement("li");
 
         item.classList.add("operation");
-        item.innerHTML = name;
+
+        if (this.app.operations[name] != null) {
+            item.innerHTML = name;
+        }
+
         this.buildRecipeOperation(item);
         document.getElementById("rec-list").appendChild(item);