fix: form dropdown, escape autocomplete dropdown items, fixes #9089

pull/9109/head
Torkel Ödegaard 8 years ago
parent e91cf28f8d
commit bf110d02d1
  1. 4
      public/app/core/components/form_dropdown/form_dropdown.ts
  2. 2
      public/app/plugins/datasource/elasticsearch/query_def.js

@ -115,7 +115,9 @@ export class FormDropdownCtrl {
this.optionCache = options;
// extract texts
let optionTexts = _.map(options, 'text');
let optionTexts = _.map(options, op => {
return _.escape(op.text);
});
// add custom values
if (this.allowCustom) {

@ -29,7 +29,7 @@ function (_) {
orderByOptions: [
{text: "Doc Count", value: '_count' },
{text: "Term value", value: '_term' },
{text: "Term value<script>alert('hello')</script>", value: '_term' },
],
orderOptions: [

Loading…
Cancel
Save