Fixing XSS vulnerability by using the proper output tags

This commit is contained in:
Nabeel Shahzad
2018-03-12 17:58:12 -05:00
parent 17f9464208
commit 8076c2d8c1
165 changed files with 1187 additions and 1187 deletions

View File

@@ -11,14 +11,14 @@
<tr>
<td>
@if(filled($user->country))
<span class="flag-icon flag-icon-{!! $user->country !!}"
title="{!! $country->alpha2($user->country)['name'] !!}"></span>
<span class="flag-icon flag-icon-{{ $user->country }}"
title="{{ $country->alpha2($user->country)['name'] }}"></span>
&nbsp;
@endif
<a href="{!! route('admin.users.edit', [$user->id]) !!}">{!! $user->name !!}</a>
<a href="{{ route('admin.users.edit', [$user->id]) }}">{{ $user->name }}</a>
</td>
<td>{!! $user->email !!}</td>
<td>{!! show_date($user->created_at) !!}</td>
<td>{{ $user->email }}</td>
<td>{{ show_date($user->created_at) }}</td>
<td class="text-center">
@if($user->state === UserState::ACTIVE)
<span class="label label-success">
@@ -27,15 +27,15 @@
@else
<span class="label label-default">
@endif
{!! UserState::label($user->state) !!}</span>
{{ UserState::label($user->state) }}</span>
</td>
<td class="text-right">
{!! Form::open(['route' => ['admin.users.destroy', $user->id], 'method' => 'delete']) !!}
<a href="{!! route('admin.users.edit', [$user->id]) !!}"
{{ Form::open(['route' => ['admin.users.destroy', $user->id], 'method' => 'delete']) }}
<a href="{{ route('admin.users.edit', [$user->id]) }}"
class='btn btn-sm btn-success btn-icon'>
<i class="fas fa-pencil-alt"></i></a>
{!! Form::button('<i class="fa fa-times"></i>', ['type' => 'submit', 'class' => 'btn btn-sm btn-danger btn-icon', 'onclick' => "return confirm('Are you sure?')"]) !!}
{!! Form::close() !!}
{{ Form::button('<i class="fa fa-times"></i>', ['type' => 'submit', 'class' => 'btn btn-sm btn-danger btn-icon', 'onclick' => "return confirm('Are you sure?')"]) }}
{{ Form::close() }}
</td>
</tr>
@endforeach