Welcome to mirror list, hosted at ThFree Co, Russian Federation.

github.com/nextcloud/gallery.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
path: root/js/vendor
diff options
context:
space:
mode:
authorOlivier Paroz <oparoz@users.noreply.github.com>2016-07-04 00:27:04 +0300
committerVincent Petry <PVince81@owncloud.com>2016-07-06 14:29:50 +0300
commitc36e2d8d8423a36cc5d09fd59012da5f085870a4 (patch)
tree517e4118553bbc9db8e1305a914057f294b9f657 /js/vendor
parente99047079333e6ac4c33412b11070feb88d3ca7f (diff)
Add more escaping
Escape folder names in share.js
Diffstat (limited to 'js/vendor')
-rw-r--r--js/vendor/owncloud/share.js2
1 files changed, 1 insertions, 1 deletions
diff --git a/js/vendor/owncloud/share.js b/js/vendor/owncloud/share.js
index 7e834dba..b31b28cf 100644
--- a/js/vendor/owncloud/share.js
+++ b/js/vendor/owncloud/share.js
@@ -296,7 +296,7 @@
showDropDown:function(itemType, itemSource, appendTo, link, possiblePermissions, filename) {
var data = OC.Share.loadItem(itemType, itemSource);
var dropDownEl;
- var html = '<div id="dropdown" class="drop shareDropDown" data-item-type="'+itemType+'" data-item-source="'+itemSource+'">';
+ var html = '<div id="dropdown" class="drop shareDropDown" data-item-type="'+escapeHTML(itemType)+'" data-item-source="'+escapeHTML(itemSource)+'">';
if (data !== false && data.reshare !== false && data.reshare.uid_owner !== undefined && data.reshare.uid_owner !== OC.currentUser) {
html += '<span class="reshare">';
if (oc_config.enable_avatars === true) {