mirror of
https://github.com/thelounge/thelounge
synced 2024-11-23 04:23:13 +00:00
Prevent link exploit
This commit is contained in:
parent
95df0ccec7
commit
0e7d3b93cd
2 changed files with 9 additions and 5 deletions
2
client/js/libs.min.js
vendored
2
client/js/libs.min.js
vendored
File diff suppressed because one or more lines are too long
|
@ -1,9 +1,10 @@
|
|||
function escape(text) {
|
||||
var e = {
|
||||
"<": "<",
|
||||
">": ">"
|
||||
">": ">",
|
||||
"'": """
|
||||
};
|
||||
return text.replace(/[<>]/g, function (c) {
|
||||
return text.replace(/[<>']/g, function (c) {
|
||||
return e[c];
|
||||
});
|
||||
}
|
||||
|
@ -18,9 +19,12 @@ Handlebars.registerHelper(
|
|||
text = escape(text);
|
||||
for (var i in urls) {
|
||||
var url = escape(urls[i]);
|
||||
var replace = url;
|
||||
if (url.indexOf("javascript:") !== 0) {
|
||||
replace = "<a href='" + url.replace(/^www/, "//www") + "' target='_blank'>" + url + "</a>";
|
||||
}
|
||||
text = text.replace(
|
||||
"$(" + i + ")",
|
||||
"<a href='" + url.replace(/^www/, "//www") + "' target='_blank'>" + url + "</a>"
|
||||
"$(" + i + ")", replace
|
||||
);
|
||||
}
|
||||
return text;
|
||||
|
|
Loading…
Reference in a new issue