mirror of
https://github.com/nocodb/nocodb.git
synced 2026-06-02 01:11:33 +00:00
fix(nocodb): prevent reflected XSS in password reset and email verify templates
This commit is contained in:
@@ -9,7 +9,7 @@ export default `<!DOCTYPE html>
|
||||
<script src="<%= ncPublicUrl %>/js/vue.2.6.14.min.js"></script>
|
||||
</head>
|
||||
<body>
|
||||
<div id="app">
|
||||
<div id="app" data-token="<%= token %>">
|
||||
<v-app>
|
||||
<v-container>
|
||||
<v-row class="justify-center">
|
||||
@@ -42,7 +42,7 @@ export default `<!DOCTYPE html>
|
||||
valid: null,
|
||||
errMsg: null,
|
||||
validForm: false,
|
||||
token: '<%= token %>',
|
||||
token: document.getElementById('app').dataset.token,
|
||||
greeting: 'Password Reset',
|
||||
formdata: {
|
||||
password: '',
|
||||
|
||||
@@ -9,7 +9,7 @@ export default `<!DOCTYPE html>
|
||||
<script src="<%= ncPublicUrl %>/js/vue.2.6.14.min.js"></script>
|
||||
</head>
|
||||
<body>
|
||||
<div id="app">
|
||||
<div id="app" data-token="<%= token %>">
|
||||
<v-app>
|
||||
<v-container>
|
||||
<v-row class="justify-center">
|
||||
@@ -68,7 +68,7 @@ export default `<!DOCTYPE html>
|
||||
data: {
|
||||
valid: null,
|
||||
validForm: false,
|
||||
token: '<%= token %>',
|
||||
token: document.getElementById('app').dataset.token,
|
||||
greeting: 'Password Reset',
|
||||
formdata: {
|
||||
password: '',
|
||||
|
||||
Reference in New Issue
Block a user