[pve-devel] applied: [PATCH manager] htmlEncode user fullnames

Thomas Lamprecht t.lamprecht at proxmox.com
Mon Oct 22 08:59:37 CEST 2018


On 10/19/18 12:36 PM, Dominik Csapak wrote:
> Signed-off-by: Dominik Csapak <d.csapak at proxmox.com>
> ---
>  www/manager6/dc/UserView.js | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/www/manager6/dc/UserView.js b/www/manager6/dc/UserView.js
> index 6dfc1041..5f8bed17 100644
> --- a/www/manager6/dc/UserView.js
> +++ b/www/manager6/dc/UserView.js
> @@ -96,7 +96,7 @@ Ext.define('PVE.dc.UserView', {
>  
>  	    var first = firstname || '';
>  	    var last = record.data.lastname || '';
> -	    return first + " " + last;
> +	    return Ext.htmlEncode(first + " " + last);
>  	};
>  
>  	var render_username = function(userid) {
> 

applied, thanks!




More information about the pve-devel mailing list