stop xss in search #71

This commit is contained in:
Hannes Mannerheim 2015-01-20 14:45:42 +01:00
parent 4e6744098d
commit 15daae0a36

View File

@ -802,7 +802,7 @@ function getStreamFromUrl() {
// {domain}/search/notice?q={urlencoded searh terms}
else if (loc.indexOf('/search/notice?q=')>-1) {
var searchToStream = loc.replace('/search/notice?q=','');
var searchToStream = replaceHtmlSpecialChars(loc.replace('/search/notice?q=',''));
if(searchToStream.length>0) {
streamToSet = 'search.json?q=' + searchToStream;
}