1
0
Fork 0
mirror of https://github.com/mperham/sidekiq.git synced 2022-11-09 13:52:34 -05:00

Queue name xss, fixes #2330

This commit is contained in:
Mike Perham 2015-05-04 08:38:51 -07:00
parent a695ff347a
commit 2178d66b66
2 changed files with 2 additions and 2 deletions

View file

@ -1,7 +1,7 @@
<header class="row">
<div class="col-sm-5">
<h3>
<%= t('CurrentMessagesInQueue', :queue => @name) %>
<%= t('CurrentMessagesInQueue', :queue => h(@name)) %>
<% if @queue.paused? %>
<span class="label label-danger"><%= t('Paused') %></span>
<% end %>

View file

@ -17,7 +17,7 @@
<td><%= number_with_delimiter(queue.size) %> </td>
<td width="20%">
<form action="<%=root_path %>queues/<%= queue.name %>" method="post">
<input class="btn btn-danger btn-xs" type="submit" name="delete" value="<%= t('Delete') %>" data-confirm="<%= t('AreYouSureDeleteQueue', :queue => queue.name) %>" />
<input class="btn btn-danger btn-xs" type="submit" name="delete" value="<%= t('Delete') %>" data-confirm="<%= t('AreYouSureDeleteQueue', :queue => h(queue.name)) %>" />
</form>
</td>
</tr>