Skip to content

Commit d00f6dc

Browse files
authored
Escape item names
1 parent 5ef669d commit d00f6dc

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

modules/ui_extra_networks.py

+2-2
Original file line numberDiff line numberDiff line change
@@ -213,9 +213,9 @@ def create_html_for_item(self, item, tabname):
213213
metadata_button = ""
214214
metadata = item.get("metadata")
215215
if metadata:
216-
metadata_button = f"<div class='metadata-button card-button' title='Show internal metadata' onclick='extraNetworksRequestMetadata(event, {quote_js(self.name)}, {quote_js(item['name'])})'></div>"
216+
metadata_button = f"<div class='metadata-button card-button' title='Show internal metadata' onclick='extraNetworksRequestMetadata(event, {quote_js(self.name)}, {quote_js(html.escape(item['name']))})'></div>"
217217

218-
edit_button = f"<div class='edit-button card-button' title='Edit metadata' onclick='extraNetworksEditUserMetadata(event, {quote_js(tabname)}, {quote_js(self.id_page)}, {quote_js(item['name'])})'></div>"
218+
edit_button = f"<div class='edit-button card-button' title='Edit metadata' onclick='extraNetworksEditUserMetadata(event, {quote_js(tabname)}, {quote_js(self.id_page)}, {quote_js(html.escape(item['name']))})'></div>"
219219

220220
local_path = ""
221221
filename = item.get("filename", "")

0 commit comments

Comments
 (0)