security fixes
This commit is contained in:
parent
b0d6a0e83f
commit
4e17234007
@ -156,19 +156,15 @@
|
||||
<script src="~/dist/jplayer/jquery.jplayer.min.js"></script>
|
||||
<script src="~/dist/add-on/jplayer.playlist.min.js"></script>
|
||||
<script>
|
||||
var verses = [];
|
||||
@* Verse text is untrusted (user-submitted content, sanitized for storage but not for
|
||||
safe embedding inside a <script> block) - it must never be spliced into a JS string
|
||||
literal via @Html.Raw as it was here before, since a verse containing a stray "'" or
|
||||
"</script>" would break out of the string. JsonSerializer.Serialize both quotes the
|
||||
value correctly and HTML/JS-escapes '<', '>' and '&' by default, so the whole array
|
||||
can be assigned directly and stays inert as data. *@
|
||||
var verses = @Html.Raw(System.Text.Json.JsonSerializer.Serialize(Model.Poem.Verses.Select(v => v.Text)));
|
||||
|
||||
@{
|
||||
<text>
|
||||
@Html.Raw($" var normaltext = { (Model.Poem.Verses.Where(v => v.VersePosition == RMuseum.Models.Ganjoor.VersePosition.Paragraph).Any() ? "true" : "false") }")
|
||||
</text>
|
||||
for (int i = 0; i < Model.Poem.Verses.Length; i++)
|
||||
{
|
||||
<text>
|
||||
@Html.Raw($"verses[{i}] = '{Model.Poem.Verses[i].Text}';")
|
||||
</text>
|
||||
}
|
||||
}
|
||||
@Html.Raw($" var normaltext = { (Model.Poem.Verses.Where(v => v.VersePosition == RMuseum.Models.Ganjoor.VersePosition.Paragraph).Any() ? "true" : "false") }")
|
||||
|
||||
function prepareclip(xmlfilename, poemtitle, auartist, oggurl, mp3url, verseArray) {
|
||||
var verseStart = [];
|
||||
|
||||
@ -244,19 +244,16 @@
|
||||
<script src="~/dist/jplayer/jquery.jplayer.min.js"></script>
|
||||
<script src="~/dist/add-on/jplayer.playlist.min.js"></script>
|
||||
<script>
|
||||
var verses = [];
|
||||
@* Verse text is untrusted (user-submitted content, sanitized for storage but not
|
||||
for safe embedding inside a <script> block) - it must never be spliced into a
|
||||
JS string literal via @Html.Raw as it was here before, since a verse containing
|
||||
a stray "'" or "</script>" would break out of the string.
|
||||
JsonSerializer.Serialize both quotes the value correctly and HTML/JS-escapes
|
||||
'<', '>' and '&' by default, so the whole array can be assigned directly and
|
||||
stays inert as data. *@
|
||||
var verses = @Html.Raw(System.Text.Json.JsonSerializer.Serialize(Model.Poem.Verses.Select(v => v.Text)));
|
||||
|
||||
@{
|
||||
<text>
|
||||
@Html.Raw($" var normaltext = { (Model.Poem.Verses.Where(v => v.VersePosition == RMuseum.Models.Ganjoor.VersePosition.Paragraph).Any() ? "true" : "false") }")
|
||||
</text>
|
||||
for (int i = 0; i < Model.Poem.Verses.Length; i++)
|
||||
{
|
||||
<text>
|
||||
@Html.Raw($"verses[{i}] = '{Model.Poem.Verses[i].Text}';")
|
||||
</text>
|
||||
}
|
||||
}
|
||||
@Html.Raw($" var normaltext = { (Model.Poem.Verses.Where(v => v.VersePosition == RMuseum.Models.Ganjoor.VersePosition.Paragraph).Any() ? "true" : "false") }")
|
||||
|
||||
function prepareclip(xmlfilename, poemtitle, auartist, oggurl, mp3url, verseArray) {
|
||||
var verseStart = [];
|
||||
|
||||
Loading…
Reference in New Issue
Block a user