Welcome to mirror list, hosted at ThFree Co, Russian Federation.

gitlab.com/gitlab-org/gitlab-foss.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorJacob Schatz <jschatz@gitlab.com>2016-04-21 19:22:15 +0300
committerJacob Schatz <jschatz@gitlab.com>2016-04-21 19:22:15 +0300
commita216ea5a342a0639da9ebc97254fb5d1e8e2d715 (patch)
treec247da634ac74cd1ff4019044ed9c15bd5575b35 /app/assets
parent7ded28ff99d89d2ba51a522992f048ed446b4ce3 (diff)
parentfd5b158765ff46617e1e00642bb266177f6d5e32 (diff)
Merge branch 'issue_15434' into 'master'
Fixes XSS injection REF: https://gitlab.com/gitlab-org/gitlab-ce/issues/15434 **Without the fix** ![xss1](/uploads/0a7b0b15fb87066965a7c73f1dbaa815/xss1.gif) **With the fix** ![xss2](/uploads/473cfa0aa80656f24c58aebf1fd97fff/xss2.gif) See merge request !1952
Diffstat (limited to 'app/assets')
-rw-r--r--app/assets/javascripts/commits.js.coffee2
1 files changed, 1 insertions, 1 deletions
diff --git a/app/assets/javascripts/commits.js.coffee b/app/assets/javascripts/commits.js.coffee
index ffd3627b1b0..0acb4c1955e 100644
--- a/app/assets/javascripts/commits.js.coffee
+++ b/app/assets/javascripts/commits.js.coffee
@@ -1,7 +1,7 @@
class @CommitsList
@timer = null
- @init: (ref, limit) ->
+ @init: (limit) ->
$("body").on "click", ".day-commits-table li.commit", (event) ->
if event.target.nodeName != "A"
location.href = $(this).attr("url")