From 4e17234007499a45a0b6e40b42506d7cdeec07b7 Mon Sep 17 00:00:00 2001 From: Hamid Reza Mohammadi Date: Sat, 26 Sep 2026 19:50:15 +0330 Subject: [PATCH] security fixes --- .../Pages/Recitations/AudioClip.cshtml | 20 +++++++----------- .../Pages/Recitations/ReportRecitation.cshtml | 21 ++++++++----------- 2 files changed, 17 insertions(+), 24 deletions(-) diff --git a/GanjooRazor/Pages/Recitations/AudioClip.cshtml b/GanjooRazor/Pages/Recitations/AudioClip.cshtml index a9506226..2f92d95f 100644 --- a/GanjooRazor/Pages/Recitations/AudioClip.cshtml +++ b/GanjooRazor/Pages/Recitations/AudioClip.cshtml @@ -156,19 +156,15 @@ " would break out of the string. JsonSerializer.Serialize both quotes the + value correctly and HTML/JS-escapes '<', '>' and '&' by default, so the whole array + can be assigned directly and stays inert as data. *@ + var verses = @Html.Raw(System.Text.Json.JsonSerializer.Serialize(Model.Poem.Verses.Select(v => v.Text))); - @{ - - @Html.Raw($" var normaltext = { (Model.Poem.Verses.Where(v => v.VersePosition == RMuseum.Models.Ganjoor.VersePosition.Paragraph).Any() ? "true" : "false") }") - - for (int i = 0; i < Model.Poem.Verses.Length; i++) - { - - @Html.Raw($"verses[{i}] = '{Model.Poem.Verses[i].Text}';") - - } - } + @Html.Raw($" var normaltext = { (Model.Poem.Verses.Where(v => v.VersePosition == RMuseum.Models.Ganjoor.VersePosition.Paragraph).Any() ? "true" : "false") }") function prepareclip(xmlfilename, poemtitle, auartist, oggurl, mp3url, verseArray) { var verseStart = []; diff --git a/GanjooRazor/Pages/Recitations/ReportRecitation.cshtml b/GanjooRazor/Pages/Recitations/ReportRecitation.cshtml index f78275d3..4c4a0313 100644 --- a/GanjooRazor/Pages/Recitations/ReportRecitation.cshtml +++ b/GanjooRazor/Pages/Recitations/ReportRecitation.cshtml @@ -244,19 +244,16 @@ " would break out of the string. + JsonSerializer.Serialize both quotes the value correctly and HTML/JS-escapes + '<', '>' and '&' by default, so the whole array can be assigned directly and + stays inert as data. *@ + var verses = @Html.Raw(System.Text.Json.JsonSerializer.Serialize(Model.Poem.Verses.Select(v => v.Text))); - @{ - - @Html.Raw($" var normaltext = { (Model.Poem.Verses.Where(v => v.VersePosition == RMuseum.Models.Ganjoor.VersePosition.Paragraph).Any() ? "true" : "false") }") - - for (int i = 0; i < Model.Poem.Verses.Length; i++) - { - - @Html.Raw($"verses[{i}] = '{Model.Poem.Verses[i].Text}';") - - } - } + @Html.Raw($" var normaltext = { (Model.Poem.Verses.Where(v => v.VersePosition == RMuseum.Models.Ganjoor.VersePosition.Paragraph).Any() ? "true" : "false") }") function prepareclip(xmlfilename, poemtitle, auartist, oggurl, mp3url, verseArray) { var verseStart = [];