Skip to content

Commit e51fb19

Browse files
XSS changes for ratings
1 parent 8afaa54 commit e51fb19

File tree

4 files changed

+8
-5
lines changed

4 files changed

+8
-5
lines changed

plugins/star-rating/frontend/public/javascripts/countly.views.js

+4-1
Original file line numberDiff line numberDiff line change
@@ -182,6 +182,7 @@
182182

183183
// these table components should be 3 different components
184184
var CommentsTable = countlyVue.views.create({
185+
mixins: [countlyVue.mixins.commonFormatters],
185186
template: CV.T("/star-rating/templates/comments-table.html"),
186187
props: {
187188
comments: Array,
@@ -821,7 +822,8 @@
821822
},
822823
mixins: [
823824
countlyVue.mixins.hasDrawers("widget"),
824-
countlyVue.mixins.auth(FEATURE_NAME)
825+
countlyVue.mixins.auth(FEATURE_NAME),
826+
countlyVue.mixins.commonFormatters
825827
],
826828
data: function() {
827829
return {
@@ -1177,6 +1179,7 @@
11771179
});
11781180

11791181
var UserFeedbackRatingsTable = countlyVue.views.create({
1182+
mixins: [countlyVue.mixins.commonFormatters],
11801183
template: CV.T('/star-rating/templates/users-feedback-ratings-table.html'),
11811184
props: {
11821185
ratings: {

plugins/star-rating/frontend/public/templates/comments-table.html

+1-1
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
</el-table-column>
1919
<el-table-column sortable="true" prop="cd" :label="i18n('feedback.time')" min-width="120">
2020
<template v-slot="rowScope">
21-
<span class="text-medium" :data-test-id="'ratings-comment-table-time-row-' + rowScope.$index" v-html="rowScope.row.cd"></span>
21+
<span class="text-medium" :data-test-id="'ratings-comment-table-time-row-' + rowScope.$index">{{unescapeHtml(rowScope.row.cd)}}</span>
2222
</template>
2323
</el-table-column>
2424
<el-table-column prop="email" :label="i18n('feedback.email')" min-width="200">

plugins/star-rating/frontend/public/templates/users-feedback-ratings-table.html

+1-1
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@
1616
</el-table-column>
1717
<el-table-column prop="time" column-key="ts" :label="i18n('feedback.time')">
1818
<template v-slot="rowScope">
19-
<span v-html="rowScope.row.ts" class="text-medium"></span>
19+
<span class="text-medium">{{unescapeHtml(rowScope.row.ts)}}</span>
2020
</template>
2121
</el-table-column>
2222
</cly-datatable-n>

plugins/star-rating/frontend/public/templates/widget-detail.html

+2-2
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@
77
<span data-test-id="ratings-detail-back-link-label">{{ i18n('feedback.back-to-rating-widgets') }}</span>
88
</div>
99
<div class="ratings-widget-detail-view__widget-name">
10-
<h3 v-html="widget.popup_header_text" class="ratings-widget-detail-view__widget-name" data-test-id="ratings-detail-widget-name-label"></h3>
10+
<h3 class="ratings-widget-detail-view__widget-name" data-test-id="ratings-detail-widget-name-label">{{unescapeHtml(widget.popup_header_text)}}</h3>
1111
</div>
1212
<div class="ratings-widget-detail-view__widget-informations bu-mt-4">
1313
<div :class="[widget.status && 'ratings-widget-detail-view__widget-status-active', !widget.status && 'ratings-widget-detail-view__widget-status-disabled', 'bu-has-text-weight-semibold text-small bu-mt-1']">
@@ -16,7 +16,7 @@ <h3 v-html="widget.popup_header_text" class="ratings-widget-detail-view__widget-
1616
</div>
1717
<div class="ratings-widget-detail-view__created-at text-medium bu-p-1 bu-ml-2"> <i class="ion-android-time" data-test-id="ratings-detail-created-at-icon"></i>
1818
<span data-test-id="ratings-detail-created-at-label">{{ i18n('feedback.created-at') }}</span>
19-
<span data-test-id="ratings-detail-created-at-value" v-html="widget.created_at"></span></div>
19+
<span data-test-id="ratings-detail-created-at-value">{{unescapeHtml(widget.created_at)}}</span></div>
2020
<div class="ratings-widget-detail-view__widget-id text-medium bu-p-1 bu-ml-2">
2121
<i data-test-id="ratings-detail-price-tag-icon" class="ion-pricetag"></i>
2222
<span data-test-id="ratings-detail-widget-id-label" class="ratings-widget-detail-view__widget-id">{{ i18n('feedback.widget-id') }} </span>

0 commit comments

Comments
 (0)