U4-7477 xss char stripping on data type names is being too agressive
This commit is contained in:
@@ -42,8 +42,8 @@ namespace Umbraco.Web.Editors
|
||||
{
|
||||
var dataType = (DataTypeSave)actionContext.ActionArguments["dataType"];
|
||||
|
||||
dataType.Name = dataType.Name.CleanForXss();
|
||||
dataType.Alias = dataType.Name.CleanForXss();
|
||||
dataType.Name = dataType.Name.CleanForXss('[', ']', '(', ')');
|
||||
dataType.Alias = dataType.Name.CleanForXss('[', ']', '(', ')');
|
||||
|
||||
//Validate that the property editor exists
|
||||
var propertyEditor = PropertyEditorResolver.Current.GetByAlias(dataType.SelectedEditor);
|
||||
|
||||
@@ -152,8 +152,8 @@ namespace Umbraco.Web.WebServices
|
||||
{
|
||||
t = new Template(templateId)
|
||||
{
|
||||
Text = templateName.CleanForXss(),
|
||||
Alias = templateAlias.CleanForXss(),
|
||||
Text = templateName.CleanForXss('[', ']', '(', ')'),
|
||||
Alias = templateAlias.CleanForXss('[', ']', '(', ')'),
|
||||
Design = templateContents
|
||||
};
|
||||
|
||||
|
||||
Reference in New Issue
Block a user