fix(title-xss): escaping text acquired from parameters to avoid any xss attacks

https://github.com/Netflix/Hystrix/pull/921
This commit is contained in:
Spencer Gibb
2015-10-05 09:29:02 -06:00
parent a7abfd4242
commit 0df6f0c0ae

View File

@@ -101,9 +101,9 @@
var poolStream = "${contextPath}/proxy.stream?origin=" + stream;
if(getUrlVars()["title"] != undefined) {
$('#title_name').html("Hystrix Stream: " + decodeURIComponent(getUrlVars()["title"]))
$('#title_name').text("Hystrix Stream: " + decodeURIComponent(getUrlVars()["title"]))
} else {
$('#title_name').html("Hystrix Stream: " + decodeURIComponent(stream))
$('#title_name').text("Hystrix Stream: " + decodeURIComponent(stream))
}
}
console.log("Command Stream: " + commandStream)