diff --git a/lensmint-public-server/server.js b/lensmint-public-server/server.js index 313c3b6..d2c5b96 100644 --- a/lensmint-public-server/server.js +++ b/lensmint-public-server/server.js @@ -6,6 +6,15 @@ require('dotenv').config(); const dbService = require('./dbService'); +function escapeHtml(str) { + return String(str) + .replace(/&/g, '&') + .replace(//g, '>') + .replace(/"/g, '"') + .replace(/'/g, '''); +} + const app = express(); const PORT = process.env.PORT || 5001; @@ -260,7 +269,7 @@ app.get('/verify/:claim_id', async (req, res) => {
The claim ID "${claim_id}" does not exist.
+The claim ID "${escapeHtml(claim_id)}" does not exist.