Enforce escaping on all template content

This commit is contained in:
Oliver Gorwits
2019-09-23 14:22:00 +01:00
parent 5f378a39ea
commit deb9b62c7f
77 changed files with 392 additions and 387 deletions

View File

@@ -18,7 +18,7 @@
// on load, check initial Report Options form state,
// and on each change to the form fields
$(document).ready(function() {
var tab = '[% report.tag %]'
var tab = '[% report.tag | html_entity %]'
var target = '#' + tab + '_pane';
// sidebar form fields should change colour and have trash icon