Skip to content

Commit

Permalink
XWIKI-20672: Sanitize template URLs
Browse files Browse the repository at this point in the history
  • Loading branch information
surli committed Feb 22, 2023
1 parent 02f1b50 commit 13875a6
Showing 1 changed file with 2 additions and 2 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -307,9 +307,9 @@
</div>
<button class="btn btn-danger confirm">$escapetool.xml($services.localization.render('delete'))</button>
#if("$!{request.xredirect}" != '')
#set($cancelUrl = "$request.xredirect")
#getSanitizedURLAttributeValue('a','href',$request.xredirect,$doc.getURL(),$cancelUrl)
#else
#set($cancelUrl = $doc.getURL())
#set($cancelUrl = $escapetool.xml($doc.getURL()))
#end
<a class="btn btn-default cancel" href="$!{escapetool.xml(${cancelUrl})}">$escapetool.xml($services.localization.render('cancel'))</a>
#end
Expand Down

0 comments on commit 13875a6

Please # to comment.