XSS fix in tabs (Thanks to @alvarodh5)
authorDarren <darren@darrenwhitlen.com>
Fri, 23 Jan 2015 13:46:41 +0000 (13:46 +0000)
committerDarren <darren@darrenwhitlen.com>
Fri, 23 Jan 2015 13:46:41 +0000 (13:46 +0000)
client/src/views/tabs.js

index 92e84d360451d3970a9f5841e99b27b63c1db480..a4477079f72a811aba45e4dcb62d1208e1d40488 100644 (file)
@@ -69,7 +69,8 @@ _kiwi.view.Tabs = Backbone.View.extend({
 
     panelAdded: function (panel) {
         // Add a tab to the panel
-        panel.tab = $('<li><span>' + (panel.get('title') || panel.get('name')) + '</span><div class="activity"></div></li>');
+        panel.tab = $('<li><span></span><div class="activity"></div></li>');
+        panel.tab.find('span').text(panel.get('title') || panel.get('name'));
 
         if (panel.isServer()) {
             panel.tab.addClass('server');