mirror of
https://github.com/node-red/node-red.git
synced 2023-10-10 13:36:53 +02:00
Escape html chars in Inject/Debug and Info pane
This commit is contained in:
parent
8a646f73b3
commit
10d9dee4aa
@ -379,7 +379,7 @@
|
|||||||
},
|
},
|
||||||
button: {
|
button: {
|
||||||
onclick: function() {
|
onclick: function() {
|
||||||
var label = this.name||this.payload;
|
var label = (this.name||this.payload).replace(/&/g,"&").replace(/</g,"<").replace(/>/g,">");
|
||||||
d3.xhr("inject/"+this.id).post(function(err,resp) {
|
d3.xhr("inject/"+this.id).post(function(err,resp) {
|
||||||
if (err) {
|
if (err) {
|
||||||
if (err.status == 404) {
|
if (err.status == 404) {
|
||||||
|
@ -156,9 +156,9 @@
|
|||||||
});
|
});
|
||||||
RED.view.redraw();
|
RED.view.redraw();
|
||||||
};
|
};
|
||||||
var name = (o.name?o.name:o.id).toString().replace(/</g,"<").replace(/>/g,">");
|
var name = (o.name?o.name:o.id).toString().replace(/&/g,"&").replace(/</g,"<").replace(/>/g,">");
|
||||||
var topic = (o.topic||"").toString().replace(/</g,"<").replace(/>/g,">");
|
var topic = (o.topic||"").toString().replace(/&/g,"&").replace(/</g,"<").replace(/>/g,">");
|
||||||
var payload = (o.msg||"").toString().replace(/</g,"<").replace(/>/g,">");
|
var payload = (o.msg||"").toString().replace(/&/g,"&").replace(/</g,"<").replace(/>/g,">");
|
||||||
msg.className = 'debug-message'+(o.level?(' debug-message-level-'+o.level):'')
|
msg.className = 'debug-message'+(o.level?(' debug-message-level-'+o.level):'')
|
||||||
msg.innerHTML = '<span class="debug-message-date">'+getTimestamp()+'</span>'+
|
msg.innerHTML = '<span class="debug-message-date">'+getTimestamp()+'</span>'+
|
||||||
'<span class="debug-message-name">['+name+']</span>'+
|
'<span class="debug-message-name">['+name+']</span>'+
|
||||||
|
@ -53,6 +53,7 @@ RED.sidebar.info = function() {
|
|||||||
if (val.length > 30) {
|
if (val.length > 30) {
|
||||||
val = val.substring(0,30)+" ...";
|
val = val.substring(0,30)+" ...";
|
||||||
}
|
}
|
||||||
|
val = val.replace(/&/g,"&").replace(/</g,"<").replace(/>/g,">");
|
||||||
} else if (type === "number") {
|
} else if (type === "number") {
|
||||||
val = val.toString();
|
val = val.toString();
|
||||||
} else if ($.isArray(val)) {
|
} else if ($.isArray(val)) {
|
||||||
|
Loading…
Reference in New Issue
Block a user