diff options
author | Max Magorsch <arzano@gentoo.org> | 2020-04-20 18:28:35 +0200 |
---|---|---|
committer | Max Magorsch <arzano@gentoo.org> | 2020-04-20 18:28:35 +0200 |
commit | e52d831e385a09802f3f94a865ba157d0eba4e84 (patch) | |
tree | 666c6ef24f2e31c9b8aebb64ebf0d9285aff7baa /pkg/app/handler | |
parent | Make the label on the login page clickable (diff) | |
download | glsamaker-e52d831e385a09802f3f94a865ba157d0eba4e84.tar.gz glsamaker-e52d831e385a09802f3f94a865ba157d0eba4e84.tar.bz2 glsamaker-e52d831e385a09802f3f94a865ba157d0eba4e84.zip |
Signed-off-by: Max Magorsch <arzano@gentoo.org>
Diffstat (limited to 'pkg/app/handler')
-rw-r--r-- | pkg/app/handler/cvetool/comments.go | 3 | ||||
-rw-r--r-- | pkg/app/handler/glsa/comments.go | 2 |
2 files changed, 3 insertions, 2 deletions
diff --git a/pkg/app/handler/cvetool/comments.go b/pkg/app/handler/cvetool/comments.go index 3d76d75..1659ea7 100644 --- a/pkg/app/handler/cvetool/comments.go +++ b/pkg/app/handler/cvetool/comments.go @@ -8,6 +8,7 @@ import ( "glsamaker/pkg/models/cve" "encoding/json" "glsamaker/pkg/models/users" + "html" "net/http" "time" ) @@ -52,7 +53,7 @@ func addNewCommment(id string, user *users.User, comment string) (cve.Comment, e CVEId: id, UserId: user.Id, User: user, - Message: comment, + Message: html.EscapeString(comment), Date: time.Now(), } diff --git a/pkg/app/handler/glsa/comments.go b/pkg/app/handler/glsa/comments.go index 1381984..bc626ef 100644 --- a/pkg/app/handler/glsa/comments.go +++ b/pkg/app/handler/glsa/comments.go @@ -91,7 +91,7 @@ func AddNewCommment(id string, user *users.User, comment string, commentType str User: user, UserBadge: user.Badge, Type: commentType, - Message: comment, + Message: html.EscapeString(comment), Date: time.Now(), } |