mirror of
https://github.com/grafana/grafana.git
synced 2025-02-25 18:55:37 -06:00
fix: form dropdown, escape autocomplete dropdown items, fixes #9089
This commit is contained in:
@@ -115,7 +115,9 @@ export class FormDropdownCtrl {
|
||||
this.optionCache = options;
|
||||
|
||||
// extract texts
|
||||
let optionTexts = _.map(options, 'text');
|
||||
let optionTexts = _.map(options, op => {
|
||||
return _.escape(op.text);
|
||||
});
|
||||
|
||||
// add custom values
|
||||
if (this.allowCustom) {
|
||||
|
||||
@@ -29,7 +29,7 @@ function (_) {
|
||||
|
||||
orderByOptions: [
|
||||
{text: "Doc Count", value: '_count' },
|
||||
{text: "Term value", value: '_term' },
|
||||
{text: "Term value<script>alert('hello')</script>", value: '_term' },
|
||||
],
|
||||
|
||||
orderOptions: [
|
||||
|
||||
Reference in New Issue
Block a user