Fixing XSS vulnerability by using the proper output tags
This commit is contained in:
@@ -12,8 +12,8 @@
|
||||
@section('scripts')
|
||||
<script type="text/javascript">
|
||||
phpvms.map.render_route_map({
|
||||
route_points: {!! json_encode($map_features['route_points']) !!},
|
||||
planned_route_line: {!! json_encode($map_features['planned_route_line']); !!},
|
||||
route_points: {{ json_encode($map_features['route_points']) }},
|
||||
planned_route_line: {{ json_encode($map_features['planned_route_line']) }},
|
||||
});
|
||||
</script>
|
||||
@endsection
|
||||
|
||||
@@ -12,7 +12,7 @@ $(document).ready(function () {
|
||||
'flight_id': btn.attr('x-id')
|
||||
},
|
||||
headers: {
|
||||
'x-api-key': "{!! Auth::user()->api_key !!}"
|
||||
'x-api-key': "{{ Auth::user()->api_key }}"
|
||||
}
|
||||
};
|
||||
|
||||
|
||||
@@ -2,30 +2,30 @@
|
||||
<div class="card">
|
||||
<div class="card-block" style="min-height: 0px">
|
||||
<div class="form-group text-right">
|
||||
{!! Form::open(['route' => 'frontend.flights.search', 'method' => 'GET', 'class'=>'form-inline pull-right']) !!}
|
||||
{{ Form::open(['route' => 'frontend.flights.search', 'method' => 'GET', 'class'=>'form-inline pull-right']) }}
|
||||
|
||||
<div>
|
||||
<p>Flight Number</p>
|
||||
{!! Form::text('flight_number', null, ['class' => 'form-control']) !!}
|
||||
{{ Form::text('flight_number', null, ['class' => 'form-control']) }}
|
||||
</div>
|
||||
|
||||
<div>
|
||||
<p>Departure Airport</p>
|
||||
{!! Form::select('dep_icao', $airports, null , ['class' => 'form-control']) !!}
|
||||
{{ Form::select('dep_icao', $airports, null , ['class' => 'form-control']) }}
|
||||
</div>
|
||||
|
||||
<div class="">
|
||||
<p>Arrival Airport</p>
|
||||
{!! Form::select('arr_icao', $airports, null , ['class' => 'form-control']) !!}
|
||||
{{ Form::select('arr_icao', $airports, null , ['class' => 'form-control']) }}
|
||||
</div>
|
||||
|
||||
<br />
|
||||
<div class="">
|
||||
{!! Form::submit('find', ['class' => 'btn btn-primary']) !!}
|
||||
<a href="{!! route('frontend.flights.index') !!}">clear</a>
|
||||
{{ Form::submit('find', ['class' => 'btn btn-primary']) }}
|
||||
<a href="{{ route('frontend.flights.index') }}">clear</a>
|
||||
</div>
|
||||
<br />
|
||||
{!! Form::close() !!}
|
||||
{{ Form::close() }}
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
@section('content')
|
||||
<div class="row">
|
||||
<div class="col-md-12">
|
||||
<h3 class="description">{!! $flight->ident !!} - {!! $flight->dpt_airport->full_name !!} to {!! $flight->arr_airport->full_name !!}</h3>
|
||||
<h3 class="description">{{ $flight->ident }} - {{ $flight->dpt_airport->full_name }} to {{ $flight->arr_airport->full_name }}</h3>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
@@ -13,24 +13,24 @@
|
||||
<table class="table">
|
||||
<tr>
|
||||
<td>Departure</td>
|
||||
<td>{!! $flight->dpt_airport->icao !!} @ {!! $flight->dpt_time !!}</td>
|
||||
<td>{{ $flight->dpt_airport->icao }} @ {{ $flight->dpt_time }}</td>
|
||||
</tr>
|
||||
|
||||
<tr>
|
||||
<td>Arrival</td>
|
||||
<td>{!! $flight->arr_airport->icao !!} @ {!! $flight->arr_time !!}</td>
|
||||
<td>{{ $flight->arr_airport->icao }} @ {{ $flight->arr_time }}</td>
|
||||
</tr>
|
||||
|
||||
<tr>
|
||||
<td>Route Code/Leg:</td>
|
||||
<td>{!! $flight->route_code ?: '-' !!}/{!! $flight->route_leg ?: '-' !!}</td>
|
||||
<td>{{ $flight->route_code ?: '-' }}/{{ $flight->route_leg ?: '-' }}</td>
|
||||
</tr>
|
||||
|
||||
<tr>
|
||||
<td>Alternate Airport</td>
|
||||
<td>
|
||||
@if($flight->alt_airport_id)
|
||||
{!! $flight->alt_airport->full_name !!}
|
||||
{{ $flight->alt_airport->full_name }}
|
||||
@else
|
||||
-
|
||||
@endif
|
||||
@@ -39,12 +39,12 @@
|
||||
|
||||
<tr>
|
||||
<td>Route</td>
|
||||
<td>{!! $flight->route !!}</td>
|
||||
<td>{{ $flight->route }}</td>
|
||||
</tr>
|
||||
|
||||
<tr>
|
||||
<td>Notes</td>
|
||||
<td>{!! $flight->notes !!}</td>
|
||||
<td>{{ $flight->notes }}</td>
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
|
||||
@@ -4,8 +4,8 @@
|
||||
<div class="row">
|
||||
<div class="col-sm-9">
|
||||
<h5>
|
||||
<a class="text-c" href="{!! route('frontend.flights.show', [$flight->id]) !!}">
|
||||
{!! $flight->ident !!}
|
||||
<a class="text-c" href="{{ route('frontend.flights.show', [$flight->id]) }}">
|
||||
{{ $flight->ident }}
|
||||
</a>
|
||||
</h5>
|
||||
</div>
|
||||
@@ -20,7 +20,7 @@
|
||||
<button class="btn btn-round btn-icon btn-icon-mini
|
||||
{{ in_array($flight->id, $saved, true) ? 'btn-info':'' }}
|
||||
save_flight"
|
||||
x-id="{!! $flight->id !!}"
|
||||
x-id="{{ $flight->id }}"
|
||||
x-saved-class="btn-info"
|
||||
type="button"
|
||||
title="Add/Remove Bid"
|
||||
@@ -32,26 +32,26 @@
|
||||
<div class="row">
|
||||
<div class="col-sm-5">
|
||||
<span class="title">DEP </span>
|
||||
{!! $flight->dpt_airport->icao !!}@if($flight->dpt_time), {!! $flight->dpt_time !!}@endif
|
||||
{{ $flight->dpt_airport->icao }}@if($flight->dpt_time), {{ $flight->dpt_time }}@endif
|
||||
<br />
|
||||
<span class="title">ARR </span>
|
||||
{!! $flight->arr_airport->icao !!}@if($flight->arr_time), {!! $flight->arr_time !!}@endif
|
||||
{{ $flight->arr_airport->icao }}@if($flight->arr_time), {{ $flight->arr_time }}@endif
|
||||
<br />
|
||||
@if($flight->distance)
|
||||
<span class="title">DISTANCE </span>
|
||||
{!! $flight->distance !!} {!! setting('units.distance') !!}
|
||||
{{ $flight->distance }} {{ setting('units.distance') }}
|
||||
@endif
|
||||
<br />
|
||||
@if($flight->level)
|
||||
<span class="title">LEVEL </span>
|
||||
{!! $flight->level !!} {!! setting('units.altitude') !!}
|
||||
{{ $flight->level }} {{ setting('units.altitude') }}
|
||||
@endif
|
||||
</div>
|
||||
<div class="col-sm-7">
|
||||
<div class="row">
|
||||
<div class="col-sm-12">
|
||||
<span class="title">ROUTE </span>
|
||||
{!! $flight->route !!}
|
||||
{{ $flight->route }}
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
Reference in New Issue
Block a user