Skip to content

Commit d7c66dc

Browse files
authored
fix: Escape the display name. (#593)
1 parent a382d32 commit d7c66dc

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

src/main/java/org/jitsi/jicofo/auth/ShibbolethHandler.java

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,7 @@
1717
*/
1818
package org.jitsi.jicofo.auth;
1919

20+
import com.google.common.html.*;
2021
import org.eclipse.jetty.server.*;
2122
import org.eclipse.jetty.server.handler.*;
2223

@@ -240,7 +241,7 @@ private void doHandle(
240241
boolean close = "true".equalsIgnoreCase(request.getParameter("close"));
241242

242243
responseWriter.println("<html><head><head/><body>");
243-
responseWriter.println("<h1>Hello " + displayName + "!<h1/>");
244+
responseWriter.println("<h1>Hello " + HtmlEscapers.htmlEscaper().escape(displayName) + "!<h1/>");
244245
if (!close)
245246
{
246247
responseWriter.println(

0 commit comments

Comments
 (0)