Merge pull request #464 from lbryio/fix/fix463_xss

Fix xss with error message
This commit is contained in:
Niko 2018-03-23 08:12:25 -04:00 committed by GitHub
commit eed63c9fe8
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -32,7 +32,7 @@ class AcquisitionActions extends Actions
{ {
return ['acquisition/youtube', [ return ['acquisition/youtube', [
'reward' => LBRY::youtubeReward(), 'reward' => LBRY::youtubeReward(),
'error_message' => $_GET['error_message'] ?? null 'error_message' => Request::encodeStringFromUser($_GET['error_message']) ?? null
]]; ]];
} }
@ -51,7 +51,7 @@ class AcquisitionActions extends Actions
return ['acquisition/youtube_status', [ return ['acquisition/youtube_status', [
'token' => $token, 'token' => $token,
'status_token' => LBRY::statusYoutube($token), 'status_token' => LBRY::statusYoutube($token),
'error_message' => $_GET['error_message'] ?? null 'error_message' => Request::encodeStringFromUser($_GET['error_message']) ?? null
]]; ]];
} }