Skip to content

Commit f211c11

Browse files
authored
Merge pull request #10942 from snipe/fixes/xss_user_requested
Fixes potential XSS vuln in user requestable results
2 parents 7479f5f + 698c7f4 commit f211c11

File tree

1 file changed

+5
-5
lines changed

1 file changed

+5
-5
lines changed

app/Http/Controllers/Api/ProfileController.php

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -30,11 +30,11 @@ public function requestedAssets()
3030
// Make sure the asset and request still exist
3131
if ($checkoutRequest && $checkoutRequest->itemRequested()) {
3232
$results['rows'][] = [
33-
'image' => $checkoutRequest->itemRequested()->present()->getImageUrl(),
34-
'name' => $checkoutRequest->itemRequested()->present()->name(),
35-
'type' => $checkoutRequest->itemType(),
36-
'qty' => $checkoutRequest->quantity,
37-
'location' => ($checkoutRequest->location()) ? $checkoutRequest->location()->name : null,
33+
'image' => e($checkoutRequest->itemRequested()->present()->getImageUrl()),
34+
'name' => e($checkoutRequest->itemRequested()->present()->name()),
35+
'type' => e($checkoutRequest->itemType()),
36+
'qty' => (int) $checkoutRequest->quantity,
37+
'location' => ($checkoutRequest->location()) ? e($checkoutRequest->location()->name) : null,
3838
'expected_checkin' => Helper::getFormattedDateObject($checkoutRequest->itemRequested()->expected_checkin, 'datetime'),
3939
'request_date' => Helper::getFormattedDateObject($checkoutRequest->created_at, 'datetime'),
4040
];

0 commit comments

Comments
 (0)