Fix dashboard html escaping and javascript redirect (#11370)

This commit is contained in:
Jellyfrog 2020-04-02 23:33:18 +02:00 committed by GitHub
parent 7c770a99d8
commit 69280b3501
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 3 additions and 3 deletions

View File

@ -36,7 +36,7 @@ if (!Auth::check()) {
$status = 'error';
$message = 'unknown error';
$dashboard_name = display($_REQUEST['dashboard_name']);
$dashboard_name = trim($_REQUEST['dashboard_name']);
if (!empty($dashboard_name) && ($dash_id = dbInsert(['dashboard_name' => $dashboard_name, 'user_id' => Auth::id()], 'dashboards'))) {
$status = 'ok';

View File

@ -426,7 +426,7 @@
if (data.status == "ok") {
toastr.success(data.message);
setTimeout(function (){
window.location.href = "{{ url('/?dashboard=') }} + dashboard_id";
window.location.href = "{{ url('/?dashboard=') }}" + dashboard_id;
}, 500);
}
else {
@ -455,7 +455,7 @@
if( data.status == "ok" ) {
toastr.success(data.message);
setTimeout(function (){
window.location.href = "{{ url('/?dashboard=') }} + data.dashboard_id";
window.location.href = "{{ url('/?dashboard=') }}" + data.dashboard_id;
}, 500);
}
else {