From 6b1f41822531c6fccef254b9626792c453bd2e7d Mon Sep 17 00:00:00 2001 From: Juanfran Date: Wed, 10 Aug 2016 11:31:40 +0200 Subject: [PATCH] [Backport] fix xss releated task --- app/partials/task/related-task-row.jade | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/app/partials/task/related-task-row.jade b/app/partials/task/related-task-row.jade index e51deda1..83fec325 100644 --- a/app/partials/task/related-task-row.jade +++ b/app/partials/task/related-task-row.jade @@ -1,9 +1,9 @@ .task-name a.clickable( - tg-nav="project-tasks-detail:project=project.slug,ref=task.ref" - title!="#<%- task.ref %> <%- task.subject %>") + tg-nav="project-tasks-detail:project=project.slug,ref=task.ref") span #<%- task.ref %> - span <%- task.subject %> + span(ng-non-bindable) <%- task.subject %> + .task-settings <% if(perms.modify_task) { %> a.edit-task(