fix XSS in webchatlink variable #63

Merged
ben merged 13 commits from alexlehm/tilde.chat:master into master 3 weeks ago

webchatlink variable comes from the json file and was echoed unencoded

webchatlink variable comes from the json file and was echoed unencoded
alexlehm added 13 commits 3 weeks ago
ben merged commit 420fd558c6 into master 3 weeks ago
ben referenced this issue from a commit 3 weeks ago
continuous-integration/drone/pr Build encountered an error
The pull request has been merged as 420fd558c6.
You can also view command line instructions.

Step 1:

From your project repository, check out a new branch and test the changes.
git checkout -b alexlehm-master master
git pull master

Step 2:

Merge the changes and update on Gitea.
git checkout master
git merge --no-ff alexlehm-master
git push origin master
Sign in to join this conversation.
No reviewers
No Label
No Milestone
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: tildeverse/tilde.chat#63
Loading…
There is no content yet.