Skip to content

Commit

Permalink
Escape HTML in profile name preview in profile settings (mastodon#9446)
Browse files Browse the repository at this point in the history
* fix non-escaped html in the profile settings

* provide a default profile text in case if there's no custom one

* update haml syntax

* simplify default profile name to username

* sanitize user-input html but display emojified icons
  • Loading branch information
pawelngei authored and hiyuki2578 committed Oct 2, 2019
1 parent f666956 commit 2bc38ed
Show file tree
Hide file tree
Showing 2 changed files with 7 additions and 2 deletions.
8 changes: 6 additions & 2 deletions app/javascript/packs/public.js
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
import escapeTextContentForBrowser from 'escape-html';
import loadPolyfills from '../mastodon/load_polyfills';
import ready from '../mastodon/ready';
import { start } from '../mastodon/common';
Expand Down Expand Up @@ -133,9 +134,12 @@ function main() {

delegate(document, '#account_display_name', 'input', ({ target }) => {
const name = document.querySelector('.card .display-name strong');

if (name) {
name.innerHTML = emojify(target.value);
if (target.value) {
name.innerHTML = emojify(escapeTextContentForBrowser(target.value));
} else {
name.textContent = document.querySelector('#default_account_display_name').textContent;
}
}
});

Expand Down
1 change: 1 addition & 0 deletions app/views/application/_card.html.haml
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@
= image_tag account.avatar.url, alt: '', width: 48, height: 48, class: 'u-photo'

.display-name
%span{id: "default_account_display_name", style: "display:none;"}= account.username
%bdi
%strong.emojify.p-name= display_name(account, custom_emojify: true)
%span
Expand Down

0 comments on commit 2bc38ed

Please sign in to comment.