Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Limit callback to only ipretFullResults and ipretResults values #3896

Merged
merged 1 commit into from Jun 23, 2023

Conversation

litvinovg
Copy link
Collaborator

What does this pull request do?

Limits callback to only ipretFullResults and ipretResults values

How should this be tested?

A description of what steps someone could take to:

  • Build and install VIVO
  • Load sample data
  • Open capability map
  • Enter Civil War Reconstruction
  • Capability map should work
  • Try using the url described in the slack thread
    /visualizationAjax?vis=capabilitymap&query=291822&callback=ipretResultsoesic<script>alert(1)<%2fscript>cwz3i&noCacheIE=1687235208332
  • Alert in the browser shouldn't appear.

Additional Notes:

Slack discussion https://vivo-project.slack.com/archives/C8RL9L98A/p1687378615914659

Interested parties

Tag (@ mention) interested parties or, if unsure, @VIVO-project/vivo-committers

@litvinovg litvinovg requested a review from chenejac June 23, 2023 12:17
Copy link
Contributor

@chenejac chenejac left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@litvinovg well done.

@chenejac chenejac merged commit b049158 into vivo-project:main Jun 23, 2023
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants