Skip to content

Commit

Permalink
fix: 修复系统设置 > 消息订阅 > 修改订阅人 因为用户名导致的 xss
Browse files Browse the repository at this point in the history
  • Loading branch information
ibuler committed Aug 8, 2023
1 parent b58c21a commit df5d15c
Showing 1 changed file with 5 additions and 4 deletions.
9 changes: 5 additions & 4 deletions src/views/settings/Message/SelectDialog.vue
Original file line number Diff line number Diff line change
Expand Up @@ -2,20 +2,21 @@
<Dialog
ref="myDialog"
:destroy-on-close="true"
width="790px"
height="720px"
v-bind="$attrs"
width="790px"
@confirm="submit"
v-on="$listeners"
>
<krryPaging ref="pageTransfer" v-bind="pagingTransfer" class="transfer" />
<krryPaging ref="pageTransfer" class="transfer" v-bind="pagingTransfer" />
</Dialog>
</template>

<script>
import Dialog from '@/components/Dialog'
import { krryPaging } from 'krry-transfer'
import { getUserList } from '@/api/users'
export default {
name: 'ListSelect',
components: {
Expand Down Expand Up @@ -47,7 +48,7 @@ export default {
}
const data = await getUserList(params)
const results = data['results'].map(item => {
return { id: item.id, label: `${item.name}(${item.username})` }
return { id: item.id, label: _.escape(`${item.name}(${item.username})`) }
})
return results
},
Expand All @@ -62,7 +63,7 @@ export default {
}
const data = await getUserList(params)
const results = data['results'].map(item => {
return { id: item.id, label: `${item.name}(${item.username})` }
return { id: item.id, label: _.escape(`${item.name}(${item.username})`) }
})
return results
},
Expand Down

0 comments on commit df5d15c

Please sign in to comment.