mirror of
				https://github.com/zadam/trilium.git
				synced 2025-10-31 10:26:08 +01:00 
			
		
		
		
	fix "XSS" in the new empty tab, closes #2145
This commit is contained in:
		| @@ -43,7 +43,7 @@ async function autocompleteSource(term, cb, options = {}) { | |||||||
|                 action: 'create-note', |                 action: 'create-note', | ||||||
|                 noteTitle: term, |                 noteTitle: term, | ||||||
|                 parentNoteId: activeNoteId || 'root', |                 parentNoteId: activeNoteId || 'root', | ||||||
|                 highlightedNotePathTitle: `Create and link child note "${term}"` |                 highlightedNotePathTitle: `Create and link child note "${utils.escapeHtml(term)}"` | ||||||
|             } |             } | ||||||
|         ].concat(results); |         ].concat(results); | ||||||
|     } |     } | ||||||
| @@ -53,7 +53,7 @@ async function autocompleteSource(term, cb, options = {}) { | |||||||
|             { |             { | ||||||
|                 action: 'external-link', |                 action: 'external-link', | ||||||
|                 externalLink: term, |                 externalLink: term, | ||||||
|                 highlightedNotePathTitle: `Insert external link to "${term}"` |                 highlightedNotePathTitle: `Insert external link to "${utils.escapeHtml(term)}"` | ||||||
|             } |             } | ||||||
|         ].concat(results); |         ].concat(results); | ||||||
|     } |     } | ||||||
|   | |||||||
		Reference in New Issue
	
	Block a user