作业评论的xss

issues25489
cxt 5 years ago
parent f620ff8bbd
commit aba3456560

@ -3,7 +3,7 @@ json.author do
end
json.id message.id
json.content message.contents_show(identity)
json.content content_safe(message.contents_show(identity))
json.time time_from_now(message.created_at)
json.hidden message.hidden
# 主贴与子贴不一致

Loading…
Cancel
Save