Fix XSS on file name in file upload

pull/833/head
Rodrigo Nascimento 11 years ago
parent 4273eb7bd0
commit 2d86186896
  1. 6
      client/lib/fileUpload.coffee

@ -33,14 +33,14 @@ readAsArrayBuffer = (file, callback) ->
Your browser does not support the audio element.
</audio>
</div>
<div class='upload-preview-title'>#{file.name}</div>
<div class='upload-preview-title'>#{Handlebars._escape(file.name)}</div>
"""
else
text = """
<div class='upload-preview'>
<div class='upload-preview-file' style='background-image: url(#{fileContent})'></div>
</div>
<div class='upload-preview-title'>#{file.name}</div>
<div class='upload-preview-title'>#{Handlebars._escape(file.name)}</div>
"""
swal
@ -147,4 +147,4 @@ readAsArrayBuffer = (file, callback) ->
Session.set 'uploading', _.without(uploading, item)
, 1000
consume()
consume()

Loading…
Cancel
Save