Skip to content

Commit 0a98ffb

Browse files
author
Michael Mrowetz
committed
#153 XSS safty improvements
1 parent 1d8f487 commit 0a98ffb

File tree

2 files changed

+2
-2
lines changed

2 files changed

+2
-2
lines changed

Diff for: src/ts/transformers/har-tabs.ts

+1-1
Original file line numberDiff line numberDiff line change
@@ -131,5 +131,5 @@ function makeImgTab(entry: Entry): WaterfallEntryTab {
131131
return makeLazyWaterfallEntryTab(
132132
"Preview",
133133
(detailsHeight: number) => `<img class="preview" style="max-height:${(detailsHeight - 100)}px"
134-
data-src="${entry.request.url}" />`);
134+
data-src="${entry.request.url.replace("\"", "&quot;")}" />`);
135135
}

Diff for: src/ts/transformers/helpers.ts

+1-1
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ export function makeDefinitionList(dlKeyValues: KvTuple[], addClass: boolean = f
2525
return dlKeyValues
2626
.filter((tuple: KvTuple) => tuple[1] !== undefined)
2727
.map((tuple) => `
28-
<dt ${makeClass(tuple[0])}>${tuple[0]}</dt>
28+
<dt ${makeClass(tuple[0])}>${escapeHtml(tuple[0])}</dt>
2929
<dd>${escapeHtml(tuple[1])}</dd>
3030
`).join("");
3131
}

0 commit comments

Comments
 (0)