webui: escape form fields. closes #12883 (#13172)

https://handlebarsjs.com/guide/expressions.html#html-escaping
This commit is contained in:
Diego Heras
2022-04-17 11:26:54 +02:00
committed by GitHub
parent c14f32482c
commit d22820080f

View File

@@ -237,15 +237,15 @@
<script id="setup-item-inputstring" type="text/x-handlebars-template">
<div class="setup-item-inputstring">
{{#if ispassword}}
<input class="form-control" type="password" value="{{{value}}}" />
<input class="form-control" type="password" value="{{value}}" />
{{else}}
<input class="form-control" type="text" value="{{{value}}}" />
<input class="form-control" type="text" value="{{value}}" />
{{/if}}
</div>
</script>
<script id="setup-item-password" type="text/x-handlebars-template">
<div class="setup-item-password">
<input class="form-control" type="password" value="{{{value}}}" />
<input class="form-control" type="password" value="{{value}}" />
</div>
</script>
<script id="setup-item-inputbool" type="text/x-handlebars-template">
@@ -291,7 +291,7 @@
</script>
<script id="setup-item-hiddendata" type="text/x-handlebars-template">
<div class="setup-item-hiddendata">
<input class="form-control" type="text" value="{{{value}}}" />
<input class="form-control" type="text" value="{{value}}" />
</div>
</script>
<script id="setup-item-alternativesitelinks" type="text/x-handlebars-template">