harsher escaping in order to fix xss
This commit is contained in:
parent
f37b9a5bd0
commit
8272eb1230
@ -105,7 +105,7 @@ async function createPost(username,text,time,specialtext,postid,isbot) {
|
||||
}
|
||||
newP.appendChild(spacerTextNode())
|
||||
// |\>.</|
|
||||
newP.innerHTML += `<button onclick="reply('${username}',${postid},'${htmlesc(text).replace("'","\\'")}')">Reply to this Post</button>`
|
||||
newP.innerHTML += `<button onclick="reply('${username}',${postid},'${htmlesc(text).replace("'","\\\\'")}')">Reply to this Post</button>`
|
||||
|
||||
newDiv.appendChild(newP)
|
||||
newDiv.innerHTML += filterPost(text)
|
||||
|
Loading…
x
Reference in New Issue
Block a user