]> source.dussan.org Git - gitea.git/commit
Immediate fix to htmlEncode user added text (#5575)
authortechknowlogick <hello@techknowlogick.com>
Fri, 21 Dec 2018 14:05:47 +0000 (09:05 -0500)
committerGitHub <noreply@github.com>
Fri, 21 Dec 2018 14:05:47 +0000 (09:05 -0500)
commitaf4626a2700aa81ecf4fcf7c81717f6715513526
treeea83a1a1c02f50fd205d7a4ee82ad2a05910e354
parent21c70e1ed27420646d0d85f044facc8c84be3d5f
Immediate fix to htmlEncode user added text (#5575)

There are likely problems remaining with the way that initCommentForm
is creating its elements. I suspect that a malformed avatar url could
be used maliciously.
public/js/index.js