Skip to content

Commit 81a0bef

Browse files
authored
Merge pull request #1148 from warcooft/patch-escape-string
fix: escape string to prevent XSS attack
2 parents a38b3cc + 9e283d3 commit 81a0bef

File tree

5 files changed

+10
-10
lines changed

5 files changed

+10
-10
lines changed

src/Views/email_2fa_show.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
<p><?= lang('Auth.confirmEmailAddress') ?></p>
1313

1414
<?php if (session('error')) : ?>
15-
<div class="alert alert-danger"><?= session('error') ?></div>
15+
<div class="alert alert-danger"><?= esc(session('error')) ?></div>
1616
<?php endif ?>
1717

1818
<form action="<?= url_to('auth-action-handle') ?>" method="post">

src/Views/email_2fa_verify.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
<p><?= lang('Auth.emailConfirmCode') ?></p>
1313

1414
<?php if (session('error') !== null) : ?>
15-
<div class="alert alert-danger"><?= session('error') ?></div>
15+
<div class="alert alert-danger"><?= esc(session('error')) ?></div>
1616
<?php endif ?>
1717

1818
<form action="<?= url_to('auth-action-verify') ?>" method="post">

src/Views/email_activate_show.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@
1010
<h5 class="card-title mb-5"><?= lang('Auth.emailActivateTitle') ?></h5>
1111

1212
<?php if (session('error')) : ?>
13-
<div class="alert alert-danger"><?= session('error') ?></div>
13+
<div class="alert alert-danger"><?= esc(session('error')) ?></div>
1414
<?php endif ?>
1515

1616
<p><?= lang('Auth.emailActivateBody') ?></p>

src/Views/login.php

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -10,22 +10,22 @@
1010
<h5 class="card-title mb-5"><?= lang('Auth.login') ?></h5>
1111

1212
<?php if (session('error') !== null) : ?>
13-
<div class="alert alert-danger" role="alert"><?= session('error') ?></div>
13+
<div class="alert alert-danger" role="alert"><?= esc(session('error')) ?></div>
1414
<?php elseif (session('errors') !== null) : ?>
1515
<div class="alert alert-danger" role="alert">
1616
<?php if (is_array(session('errors'))) : ?>
1717
<?php foreach (session('errors') as $error) : ?>
18-
<?= $error ?>
18+
<?= esc($error) ?>
1919
<br>
2020
<?php endforeach ?>
2121
<?php else : ?>
22-
<?= session('errors') ?>
22+
<?= esc(session('errors')) ?>
2323
<?php endif ?>
2424
</div>
2525
<?php endif ?>
2626

2727
<?php if (session('message') !== null) : ?>
28-
<div class="alert alert-success" role="alert"><?= session('message') ?></div>
28+
<div class="alert alert-success" role="alert"><?= esc(session('message')) ?></div>
2929
<?php endif ?>
3030

3131
<form action="<?= url_to('login') ?>" method="post">

src/Views/register.php

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -10,16 +10,16 @@
1010
<h5 class="card-title mb-5"><?= lang('Auth.register') ?></h5>
1111

1212
<?php if (session('error') !== null) : ?>
13-
<div class="alert alert-danger" role="alert"><?= session('error') ?></div>
13+
<div class="alert alert-danger" role="alert"><?= esc(session('error')) ?></div>
1414
<?php elseif (session('errors') !== null) : ?>
1515
<div class="alert alert-danger" role="alert">
1616
<?php if (is_array(session('errors'))) : ?>
1717
<?php foreach (session('errors') as $error) : ?>
18-
<?= $error ?>
18+
<?= esc($error) ?>
1919
<br>
2020
<?php endforeach ?>
2121
<?php else : ?>
22-
<?= session('errors') ?>
22+
<?= esc(session('errors')) ?>
2323
<?php endif ?>
2424
</div>
2525
<?php endif ?>

0 commit comments

Comments
 (0)