mirror of
https://github.com/wallabag/wallabag.git
synced 2025-04-23 18:34:06 +00:00
Fix XSS on username on share page
This commit is contained in:
parent
784bc1393c
commit
bd4c71682e
1 changed files with 1 additions and 1 deletions
|
@ -28,7 +28,7 @@
|
||||||
<header class="block">
|
<header class="block">
|
||||||
<h1>{{ entry.title|e|raw }}</h1>
|
<h1>{{ entry.title|e|raw }}</h1>
|
||||||
<a href="{{ entry.url|e }}" target="_blank" rel="noopener" title="{{ 'entry.view.original_article'|trans }} : {{ entry.title|e|raw }}" class="tool">{{ entry.domainName|removeWww }}</a>
|
<a href="{{ entry.url|e }}" target="_blank" rel="noopener" title="{{ 'entry.view.original_article'|trans }} : {{ entry.title|e|raw }}" class="tool">{{ entry.domainName|removeWww }}</a>
|
||||||
<p class="shared-by">{{ "entry.public.shared_by_wallabag"|trans({'%wallabag_instance%': url('homepage'), '%username%': entry.user.username})|raw }}.</p>
|
<p class="shared-by">{{ "entry.public.shared_by_wallabag"|trans({'%wallabag_instance%': url('homepage'), '%username%': entry.user.username|escape})|raw }}.</p>
|
||||||
</header>
|
</header>
|
||||||
<article class="block">
|
<article class="block">
|
||||||
{{ entry.content | raw }}
|
{{ entry.content | raw }}
|
||||||
|
|
Loading…
Reference in a new issue