Skip to content

Commit 896e4a3

Browse files
Ruben ArakelyanBevan Loon
Ruben Arakelyan
authored and
Bevan Loon
committed
Sanitise govspeak fields
This commit adds sanitisation to govspeak metadata fields to prevent script injection.
1 parent 2948b8a commit 896e4a3

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

app/views/components/_important-metadata.html.erb

+3-3
Original file line numberDiff line numberDiff line change
@@ -8,12 +8,12 @@
88
<% if items.any? %>
99
<div class="app-c-important-metadata<%= margin_bottom_class %>">
1010
<% if title %>
11-
<h2 class="app-c-important-metadata__title"><%= title %></h2>
11+
<h2 class="app-c-important-metadata__title"><%= sanitize(title) %></h2>
1212
<% end %>
1313
<dl data-module="track-click">
1414
<% items.each do |title, definition| %>
15-
<dt class="app-c-important-metadata__term"><%= title %>: </dt>
16-
<dd class="app-c-important-metadata__definition"><%= definition %></dd>
15+
<dt class="app-c-important-metadata__term"><%= sanitize (title) %>: </dt>
16+
<dd class="app-c-important-metadata__definition"><%= sanitize (definition) %></dd>
1717
<% end %>
1818
</dl>
1919
</div>

0 commit comments

Comments
 (0)