security fixes

This commit is contained in:
Hamid Reza Mohammadi 2026-09-26 19:50:15 +03:30
parent b0d6a0e83f
commit 4e17234007
2 changed files with 17 additions and 24 deletions

View File

@ -156,19 +156,15 @@
<script src="~/dist/jplayer/jquery.jplayer.min.js"></script>
<script src="~/dist/add-on/jplayer.playlist.min.js"></script>
<script>
var verses = [];
@* Verse text is untrusted (user-submitted content, sanitized for storage but not for
safe embedding inside a <script> block) - it must never be spliced into a JS string
literal via @Html.Raw as it was here before, since a verse containing a stray "'" or
"</script>" would break out of the string. JsonSerializer.Serialize both quotes the
value correctly and HTML/JS-escapes '<', '>' and '&' by default, so the whole array
can be assigned directly and stays inert as data. *@
var verses = @Html.Raw(System.Text.Json.JsonSerializer.Serialize(Model.Poem.Verses.Select(v => v.Text)));
@{
<text>
@Html.Raw($" var normaltext = { (Model.Poem.Verses.Where(v => v.VersePosition == RMuseum.Models.Ganjoor.VersePosition.Paragraph).Any() ? "true" : "false") }")
</text>
for (int i = 0; i < Model.Poem.Verses.Length; i++)
{
<text>
@Html.Raw($"verses[{i}] = '{Model.Poem.Verses[i].Text}';")
</text>
}
}
@Html.Raw($" var normaltext = { (Model.Poem.Verses.Where(v => v.VersePosition == RMuseum.Models.Ganjoor.VersePosition.Paragraph).Any() ? "true" : "false") }")
function prepareclip(xmlfilename, poemtitle, auartist, oggurl, mp3url, verseArray) {
var verseStart = [];

View File

@ -244,19 +244,16 @@
<script src="~/dist/jplayer/jquery.jplayer.min.js"></script>
<script src="~/dist/add-on/jplayer.playlist.min.js"></script>
<script>
var verses = [];
@* Verse text is untrusted (user-submitted content, sanitized for storage but not
for safe embedding inside a <script> block) - it must never be spliced into a
JS string literal via @Html.Raw as it was here before, since a verse containing
a stray "'" or "</script>" would break out of the string.
JsonSerializer.Serialize both quotes the value correctly and HTML/JS-escapes
'<', '>' and '&' by default, so the whole array can be assigned directly and
stays inert as data. *@
var verses = @Html.Raw(System.Text.Json.JsonSerializer.Serialize(Model.Poem.Verses.Select(v => v.Text)));
@{
<text>
@Html.Raw($" var normaltext = { (Model.Poem.Verses.Where(v => v.VersePosition == RMuseum.Models.Ganjoor.VersePosition.Paragraph).Any() ? "true" : "false") }")
</text>
for (int i = 0; i < Model.Poem.Verses.Length; i++)
{
<text>
@Html.Raw($"verses[{i}] = '{Model.Poem.Verses[i].Text}';")
</text>
}
}
@Html.Raw($" var normaltext = { (Model.Poem.Verses.Where(v => v.VersePosition == RMuseum.Models.Ganjoor.VersePosition.Paragraph).Any() ? "true" : "false") }")
function prepareclip(xmlfilename, poemtitle, auartist, oggurl, mp3url, verseArray) {
var verseStart = [];