Skip to content

Commit 335c2fb

Browse files
committed
chore: fix XSS vulnerability in test page
1 parent 919ef22 commit 335c2fb

1 file changed

Lines changed: 5 additions & 5 deletions

File tree

worker-console.html

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -521,14 +521,14 @@ <h1>Worker Console</h1>
521521

522522
messageEl.innerHTML = `
523523
<div class="message-header">
524-
<span class="message-user">${messageData.user?.name || messageData.user?.id || 'Unknown'}</span>
525-
<span class="message-time">${time}</span>
524+
<span class="message-user">${this.escapeHtml(messageData.user?.name || messageData.user?.id || 'Unknown')}</span>
525+
<span class="message-time">${this.escapeHtml(time)}</span>
526526
</div>
527527
<div class="message-text">${this.escapeHtml(messageData.text || '')}</div>
528528
<div class="message-meta">
529-
<span>Room: ${messageData.room || 'general'}</span>
530-
<span>ID: ${messageData.messageId || messageData.id || '-'}</span>
531-
<span>From: ${messageData.instanceId || '-'}</span>
529+
<span>Room: ${this.escapeHtml(messageData.room || 'general')}</span>
530+
<span>ID: ${this.escapeHtml(messageData.messageId || messageData.id || '-')}</span>
531+
<span>From: ${this.escapeHtml(messageData.instanceId || '-')}</span>
532532
</div>
533533
`
534534

0 commit comments

Comments
 (0)