From 701de269f22f2e6760b3fdbeaaf2f3730fd45f52 Mon Sep 17 00:00:00 2001 From: Andrej Date: Tue, 26 Sep 2023 14:19:17 +0200 Subject: [PATCH] Escape inventory column names [SCI-9362] --- app/assets/javascripts/repository_columns/index.js | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/app/assets/javascripts/repository_columns/index.js b/app/assets/javascripts/repository_columns/index.js index e4db50832..b95f6f630 100644 --- a/app/assets/javascripts/repository_columns/index.js +++ b/app/assets/javascripts/repository_columns/index.js @@ -1,6 +1,6 @@ /* global I18n HelperModule truncateLongString animateSpinner RepositoryListColumnType RepositoryStockColumnType */ /* global RepositoryDatatable RepositoryStatusColumnType RepositoryChecklistColumnType dropdownSelector RepositoryDateTimeColumnType */ -/* global RepositoryDateColumnType RepositoryDatatable */ +/* global RepositoryDateColumnType RepositoryDatatable _ */ /* eslint-disable no-restricted-globals */ @@ -297,6 +297,8 @@ var RepositoryColumns = (function() { } else { thederName = el.innerText; } + thederName = _.escape(thederName); + if (['row-name', 'archived-by', 'archived-on'].includes(el.id)) { visClass = ''; visText = '';