1
0
مراية لـ https://github.com/postalserver/postal.git تم المزامنة 2026-03-03 06:14:06 +00:00

fix(deliveries): escape delivery details to prevent HTML injection

هذا الالتزام موجود في:
Adam Cooke
2026-02-01 14:48:54 +00:00
الأصل b7e5232e07
التزام 11419f9914

عرض الملف

@@ -3,6 +3,7 @@
module ApplicationHelper module ApplicationHelper
def format_delivery_details(server, text) def format_delivery_details(server, text)
text = h(text)
text.gsub!(/<msg:(\d+)>/) do text.gsub!(/<msg:(\d+)>/) do
id = ::Regexp.last_match(1).to_i id = ::Regexp.last_match(1).to_i
link_to("message ##{id}", organization_server_message_path(server.organization, server, id), class: "u-link") link_to("message ##{id}", organization_server_message_path(server.organization, server, id), class: "u-link")