Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
G
gitlab-ce
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Issues
0
Issues
0
List
Boards
Labels
Milestones
Merge Requests
1
Merge Requests
1
Analytics
Analytics
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Commits
Issue Boards
Open sidebar
nexedi
gitlab-ce
Commits
9e8d0829
Commit
9e8d0829
authored
May 21, 2018
by
Phil Hughes
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Escape user names in access dropdowns
parent
7701c4ba
Changes
2
Hide whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
14 additions
and
1 deletion
+14
-1
ee/app/assets/javascripts/projects/settings/access_dropdown.js
...p/assets/javascripts/projects/settings/access_dropdown.js
+1
-1
spec/javascripts/ee/projects/settings/access_dropdown_spec.js
.../javascripts/ee/projects/settings/access_dropdown_spec.js
+13
-0
No files found.
ee/app/assets/javascripts/projects/settings/access_dropdown.js
View file @
9e8d0829
...
...
@@ -458,7 +458,7 @@ export default class AccessDropdown {
<li>
<a href="#" class="
${
isActiveClass
}
">
<img src="
${
user
.
avatar_url
}
" class="avatar avatar-inline" width="30">
<strong class="dropdown-menu-user-full-name">
${
user
.
name
}
</strong>
<strong class="dropdown-menu-user-full-name">
${
_
.
escape
(
user
.
name
)
}
</strong>
<span class="dropdown-menu-user-username">
${
user
.
username
}
</span>
</a>
</li>
...
...
spec/javascripts/ee/projects/settings/access_dropdown_spec.js
View file @
9e8d0829
...
...
@@ -123,4 +123,17 @@ describe('AccessDropdown', () => {
});
});
});
describe
(
'
userRowHtml
'
,
()
=>
{
it
(
'
escapes users name
'
,
()
=>
{
const
user
=
{
avatar_url
:
''
,
name
:
'
<img src=x onerror=alert(document.domain)>
'
,
username
:
'
test
'
,
};
const
template
=
dropdown
.
userRowHtml
(
user
);
expect
(
template
).
not
.
toContain
(
user
.
name
);
});
});
});
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment