escape labelColor, icon, cover:position, validate toPid

This commit is contained in:
Barış Soner Uşaklı
2016-12-17 16:00:39 +03:00
parent a043876d00
commit 4ff3d06f90
5 changed files with 26 additions and 8 deletions

View File

@@ -9,7 +9,7 @@ var plugins = require('../plugins');
var user = require('../user');
var topics = require('../topics');
var categories = require('../categories');
var utils = require('../../public/src/utils');
module.exports = function (Posts) {
@@ -24,6 +24,10 @@ module.exports = function (Posts) {
return callback(new Error('[[error:invalid-uid]]'));
}
if (data.toPid && !utils.isNumber(data.toPid)) {
return callback(new Error('[[error:invalid-pid]]'));
}
var postData;
async.waterfall([