From cd5bb9f1064fa6f57fd5ec26a0be51c2934122ee Mon Sep 17 00:00:00 2001 From: celestora Date: Wed, 29 Jan 2025 23:06:56 +0200 Subject: [PATCH] #1215 fix(im): escape html in sent messages too --- Web/Presenters/templates/Messenger/App.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Web/Presenters/templates/Messenger/App.xml b/Web/Presenters/templates/Messenger/App.xml index ac3acf0b..79002373 100644 --- a/Web/Presenters/templates/Messenger/App.xml +++ b/Web/Presenters/templates/Messenger/App.xml @@ -232,7 +232,7 @@ sendMessage(content) { console.debug("New outcoming message. Pushing preview to local stack."); - let tempId = this.newMessage(content); + let tempId = this.newMessage(escapeHtml(content)); let msgData = new FormData(); msgData.set("content", content);