mirror of
https://github.com/open-metadata/OpenMetadata.git
synced 2026-01-06 04:26:57 +00:00
* fix xss vul #22460 * fix the test and minor changes --------- Co-authored-by: Sriharsha Chintalapani <harshach@users.noreply.github.com> Co-authored-by: Ashish Gupta <ashish@getcollate.io>
This commit is contained in:
parent
ddddeaf117
commit
79bd7d2715
@ -116,7 +116,7 @@ describe('Feed Utils', () => {
|
||||
const result = getBackendFormat(message);
|
||||
|
||||
// eslint-disable-next-line no-useless-escape
|
||||
const expectedResult = `<#E::user::\"admin\"|<#E::user::admin|[@admin](http://localhost:3000/users/admin)>> test`;
|
||||
const expectedResult = `<#E::user::\"admin\"|<#E::user::admin|[@admin](http://localhost:3000/users/admin)>> test`;
|
||||
|
||||
expect(result).toStrictEqual(expectedResult);
|
||||
});
|
||||
@ -126,7 +126,7 @@ describe('Feed Utils', () => {
|
||||
const result = getBackendFormat(message);
|
||||
|
||||
// eslint-disable-next-line no-useless-escape
|
||||
const expectedResult = `<#E::user::\"admin.test\"|<#E::user::%22admin.test%22|[@admin.test](http://localhost:3000/users/%22admin.test%22)>> test`;
|
||||
const expectedResult = `<#E::user::\"admin.test\"|<#E::user::%22admin.test%22|[@admin.test](http://localhost:3000/users/%22admin.test%22)>> test`;
|
||||
|
||||
expect(result).toStrictEqual(expectedResult);
|
||||
});
|
||||
|
||||
@ -78,6 +78,7 @@ import {
|
||||
getImageWithResolutionAndFallback,
|
||||
ImageQuality,
|
||||
} from './ProfilerUtils';
|
||||
import { getSanitizeContent } from './sanitize.utils';
|
||||
import { getDecodedFqn, getEncodedFqn } from './StringsUtils';
|
||||
import { showErrorToast } from './ToastUtils';
|
||||
|
||||
@ -329,7 +330,7 @@ export const getBackendFormat = (message: string) => {
|
||||
updatedMessage = updatedMessage.replaceAll(h, entityLink);
|
||||
});
|
||||
|
||||
return updatedMessage;
|
||||
return getSanitizeContent(updatedMessage);
|
||||
};
|
||||
|
||||
export const getFrontEndFormat = (message: string) => {
|
||||
@ -343,7 +344,7 @@ export const getFrontEndFormat = (message: string) => {
|
||||
updatedMessage = updatedMessage.replaceAll(m, markdownLink);
|
||||
});
|
||||
|
||||
return updatedMessage;
|
||||
return getSanitizeContent(updatedMessage);
|
||||
};
|
||||
|
||||
export const getUpdatedThread = (id: string) => {
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user