summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorEarl Warren <earl-warren@noreply.codeberg.org>2024-09-06 13:15:13 +0200
committerEarl Warren <earl-warren@noreply.codeberg.org>2024-09-06 13:15:13 +0200
commit7644435aed0ed84ce6b4ad8887807df6184d75ff (patch)
tree09a3d028e011cf59d8cb847da84eb816ecc2533b
parentMerge pull request 'Update dependency webpack to v5.94.0 [SECURITY] (v7.0/for... (diff)
parentfix: replace v-html with v-text in branch search inputbox (diff)
downloadforgejo-7644435aed0ed84ce6b4ad8887807df6184d75ff.tar.xz
forgejo-7644435aed0ed84ce6b4ad8887807df6184d75ff.zip
Merge pull request '[v7.0/forgejo] replace v-html with v-text in branch search inputbox for XSS protection' (#5246) from bp-v7.0/forgejo-bb8796b into v7.0/forgejov7.0.9
Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/5246 Reviewed-by: Earl Warren <earl-warren@noreply.codeberg.org>
-rw-r--r--web_src/js/components/RepoBranchTagSelector.vue6
1 files changed, 2 insertions, 4 deletions
diff --git a/web_src/js/components/RepoBranchTagSelector.vue b/web_src/js/components/RepoBranchTagSelector.vue
index 4e977ab185..1a02157f7b 100644
--- a/web_src/js/components/RepoBranchTagSelector.vue
+++ b/web_src/js/components/RepoBranchTagSelector.vue
@@ -289,13 +289,11 @@ export default sfc; // activate IDE's Vue plugin
<a href="#" @click="createNewBranch()">
<div v-show="shouldCreateTag">
<i class="reference tags icon"/>
- <!-- eslint-disable-next-line vue/no-v-html -->
- <span v-html="textCreateTag.replace('%s', searchTerm)"/>
+ <span v-text="textCreateTag.replace('%s', searchTerm)"/>
</div>
<div v-show="!shouldCreateTag">
<svg-icon name="octicon-git-branch"/>
- <!-- eslint-disable-next-line vue/no-v-html -->
- <span v-html="textCreateBranch.replace('%s', searchTerm)"/>
+ <span v-text="textCreateBranch.replace('%s', searchTerm)"/>
</div>
<div class="text small">
<span v-if="isViewBranch || release">{{ textCreateBranchFrom.replace('%s', branchName) }}</span>