fix(client): unescaped HTML in bookmarked notes & folders

This commit is contained in:
Elian Doran 2024-12-22 22:23:26 +02:00
parent 0bad36b9f2
commit 9bdee7afff
No known key found for this signature in database
2 changed files with 10 additions and 9 deletions

View File

@ -1,5 +1,6 @@
import RightDropdownButtonWidget from "./right_dropdown_button.js";
import linkService from "../../services/link.js";
import utils from "../../services/utils.js";
const DROPDOWN_TPL = `
<div class="bookmark-folder-widget">
@ -44,7 +45,7 @@ const DROPDOWN_TPL = `
export default class BookmarkFolderWidget extends RightDropdownButtonWidget {
constructor(note) {
super(note.title, note.getIcon(), DROPDOWN_TPL);
super(utils.escapeHtml(note.title), note.getIcon(), DROPDOWN_TPL);
this.note = note;
}

View File

@ -9,7 +9,7 @@ export default class OpenNoteButtonWidget extends OnClickButtonWidget {
this.noteToOpen = noteToOpen;
this.title(() => this.noteToOpen.title)
this.title(() => utils.escapeHtml(this.noteToOpen.title))
.icon(() => this.noteToOpen.getIcon())
.onClick((widget, evt) => this.launch(evt))
.onAuxClick((widget, evt) => this.launch(evt))