We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent b758321 commit 3f8e447Copy full SHA for 3f8e447
models/user/user.go
@@ -8,6 +8,7 @@ import (
8
"context"
9
"encoding/hex"
10
"fmt"
11
+ "html"
12
"html/template"
13
"net/url"
14
"os"
@@ -425,10 +426,10 @@ func (u *User) GetSearchNameHTML() template.HTML {
425
426
if setting.UI.DefaultShowFullName {
427
trimmed := strings.TrimSpace(u.FullName)
428
if len(trimmed) > 0 {
- return template.HTML(fmt.Sprintf(`%s<span class="text search-fullname"> %s</span>`, u.Name, trimmed))
429
+ return template.HTML(fmt.Sprintf(`%s<span class="text search-fullname"> %s</span>`, html.EscapeString(u.Name), html.EscapeString(trimmed)))
430
}
431
- return template.HTML(u.Name)
432
+ return template.HTML(html.EscapeString(u.Name))
433
434
435
func gitSafeName(name string) string {
0 commit comments