fix "XSS" in the new empty tab, closes #2145

This commit is contained in:
zadam 2021-10-31 23:12:24 +01:00
parent b0c0ed8512
commit 7e41226549

View file

@ -43,7 +43,7 @@ async function autocompleteSource(term, cb, options = {}) {
action: 'create-note',
noteTitle: term,
parentNoteId: activeNoteId || 'root',
highlightedNotePathTitle: `Create and link child note "${term}"`
highlightedNotePathTitle: `Create and link child note "${utils.escapeHtml(term)}"`
}
].concat(results);
}
@ -53,7 +53,7 @@ async function autocompleteSource(term, cb, options = {}) {
{
action: 'external-link',
externalLink: term,
highlightedNotePathTitle: `Insert external link to "${term}"`
highlightedNotePathTitle: `Insert external link to "${utils.escapeHtml(term)}"`
}
].concat(results);
}