Skip to content

Commit d547210

Browse files
committed
XWIKI-20352: Sanitize template URLs
1 parent e80d22d commit d547210

File tree

1 file changed

+3
-3
lines changed
  • xwiki-platform-core/xwiki-platform-flamingo/xwiki-platform-flamingo-skin/xwiki-platform-flamingo-skin-resources/src/main/resources/flamingo

1 file changed

+3
-3
lines changed

xwiki-platform-core/xwiki-platform-flamingo/xwiki-platform-flamingo-skin/xwiki-platform-flamingo-skin-resources/src/main/resources/flamingo/restore.vm

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -178,9 +178,9 @@
178178
</div>
179179
<button class="btn btn-primary">$services.localization.render('core.restore.confirm.yes')</button>
180180
#if("$!{request.xredirect}" != '')
181-
#set($cancelUrl = "$request.xredirect")
181+
#getSanitizedURLAttributeValue('a','href',$request.xredirect,$doc.getURL(),$cancelUrl)
182182
#else
183-
#set($cancelUrl = $doc.getURL())
183+
#set($cancelUrl = $escapetool.xml($doc.getURL()))
184184
#end
185-
<a class="btn btn-default" href="$!{escapetool.xml(${cancelUrl})}">$services.localization.render('core.restore.confirm.no')</a>
185+
<a class="btn btn-default" href="$cancelUrl">$services.localization.render('core.restore.confirm.no')</a>
186186
#end

0 commit comments

Comments
 (0)