Skip to content

Commit 3f8e447

Browse files
committed
escape strings
1 parent b758321 commit 3f8e447

File tree

1 file changed

+3
-2
lines changed

1 file changed

+3
-2
lines changed

models/user/user.go

+3-2
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ import (
88
"context"
99
"encoding/hex"
1010
"fmt"
11+
"html"
1112
"html/template"
1213
"net/url"
1314
"os"
@@ -425,10 +426,10 @@ func (u *User) GetSearchNameHTML() template.HTML {
425426
if setting.UI.DefaultShowFullName {
426427
trimmed := strings.TrimSpace(u.FullName)
427428
if len(trimmed) > 0 {
428-
return template.HTML(fmt.Sprintf(`%s<span class="text search-fullname"> %s</span>`, u.Name, trimmed))
429+
return template.HTML(fmt.Sprintf(`%s<span class="text search-fullname"> %s</span>`, html.EscapeString(u.Name), html.EscapeString(trimmed)))
429430
}
430431
}
431-
return template.HTML(u.Name)
432+
return template.HTML(html.EscapeString(u.Name))
432433
}
433434

434435
func gitSafeName(name string) string {

0 commit comments

Comments
 (0)