mirror of
https://github.com/yu-i-i/overleaf-cep.git
synced 2026-05-30 20:31:34 +02:00
sanitise the ref for universities site. and remove unneeded sanitise
This commit is contained in:
@@ -5,7 +5,6 @@ projectDuplicator = require("./ProjectDuplicator")
|
||||
projectCreationHandler = require("./ProjectCreationHandler")
|
||||
editorController = require("../Editor/EditorController")
|
||||
metrics = require('../../infrastructure/Metrics')
|
||||
sanitize = require('sanitizer')
|
||||
Project = require('../../models/Project').Project
|
||||
User = require('../../models/User').User
|
||||
TagsHandler = require("../Tags/TagsHandler")
|
||||
|
||||
@@ -4,6 +4,7 @@ logger = require("logger-sharelatex")
|
||||
_ = require("underscore")
|
||||
ErrorController = require "../Errors/ErrorController"
|
||||
StaticPageHelpers = require("./StaticPageHelpers")
|
||||
sanitize = require('sanitizer')
|
||||
|
||||
module.exports = UniversityController =
|
||||
|
||||
@@ -20,7 +21,7 @@ module.exports = UniversityController =
|
||||
data = data.trim()
|
||||
try
|
||||
data = JSON.parse(data)
|
||||
data.content = data.content.replace(/__ref__/g, req.query.ref)
|
||||
data.content = data.content.replace(/__ref__/g, sanitize.escape(req.query.ref))
|
||||
catch err
|
||||
logger.err err:err, data:data, "error parsing data from data"
|
||||
res.render "university/university_holder", data
|
||||
|
||||
Reference in New Issue
Block a user