1
0
Fork 0
mirror of https://github.com/jellyfin/jellyfin-web synced 2025-03-30 19:56:21 +00:00

Merge pull request #2676 from thornbill/fix-displaymessage-xss

(cherry picked from commit 70b41ff005)
Signed-off-by: Joshua M. Boniface <joshua@boniface.me>
This commit is contained in:
Anthony Lavado 2021-05-21 00:32:37 -04:00 committed by Joshua M. Boniface
parent dfcfaad39c
commit 4c1a301bdb

View file

@ -22,7 +22,7 @@ export default function (options) {
const elem = document.createElement('div');
elem.classList.add('toast');
elem.innerHTML = options.text;
elem.textContent = options.text;
document.body.appendChild(elem);