Fixing XSS vulnerability by using the proper output tags

This commit is contained in:
Nabeel Shahzad
2018-03-12 17:58:12 -05:00
parent 17f9464208
commit 8076c2d8c1
165 changed files with 1187 additions and 1187 deletions
@@ -12,8 +12,8 @@
@section('scripts')
<script type="text/javascript">
phpvms.map.render_route_map({
route_points: {!! json_encode($map_features['route_points']) !!},
planned_route_line: {!! json_encode($map_features['planned_route_line']); !!},
route_points: {{ json_encode($map_features['route_points']) }},
planned_route_line: {{ json_encode($map_features['planned_route_line']) }},
});
</script>
@endsection
@@ -12,7 +12,7 @@ $(document).ready(function () {
'flight_id': btn.attr('x-id')
},
headers: {
'x-api-key': "{!! Auth::user()->api_key !!}"
'x-api-key': "{{ Auth::user()->api_key }}"
}
};
@@ -2,30 +2,30 @@
<div class="card">
<div class="card-block" style="min-height: 0px">
<div class="form-group text-right">
{!! Form::open(['route' => 'frontend.flights.search', 'method' => 'GET', 'class'=>'form-inline pull-right']) !!}
{{ Form::open(['route' => 'frontend.flights.search', 'method' => 'GET', 'class'=>'form-inline pull-right']) }}
<div>
<p>Flight Number</p>
{!! Form::text('flight_number', null, ['class' => 'form-control']) !!}
{{ Form::text('flight_number', null, ['class' => 'form-control']) }}
</div>
<div>
<p>Departure Airport</p>
{!! Form::select('dep_icao', $airports, null , ['class' => 'form-control']) !!}
{{ Form::select('dep_icao', $airports, null , ['class' => 'form-control']) }}
</div>
<div class="">
<p>Arrival Airport</p>
{!! Form::select('arr_icao', $airports, null , ['class' => 'form-control']) !!}
{{ Form::select('arr_icao', $airports, null , ['class' => 'form-control']) }}
</div>
<br />
<div class="">
{!! Form::submit('find', ['class' => 'btn btn-primary']) !!}&nbsp;
<a href="{!! route('frontend.flights.index') !!}">clear</a>
{{ Form::submit('find', ['class' => 'btn btn-primary']) }}&nbsp;
<a href="{{ route('frontend.flights.index') }}">clear</a>
</div>
<br />
{!! Form::close() !!}
{{ Form::close() }}
</div>
</div>
</div>
@@ -4,7 +4,7 @@
@section('content')
<div class="row">
<div class="col-md-12">
<h3 class="description">{!! $flight->ident !!} - {!! $flight->dpt_airport->full_name !!} to {!! $flight->arr_airport->full_name !!}</h3>
<h3 class="description">{{ $flight->ident }} - {{ $flight->dpt_airport->full_name }} to {{ $flight->arr_airport->full_name }}</h3>
</div>
</div>
@@ -13,24 +13,24 @@
<table class="table">
<tr>
<td>Departure</td>
<td>{!! $flight->dpt_airport->icao !!} @ {!! $flight->dpt_time !!}</td>
<td>{{ $flight->dpt_airport->icao }} @ {{ $flight->dpt_time }}</td>
</tr>
<tr>
<td>Arrival</td>
<td>{!! $flight->arr_airport->icao !!} @ {!! $flight->arr_time !!}</td>
<td>{{ $flight->arr_airport->icao }} @ {{ $flight->arr_time }}</td>
</tr>
<tr>
<td>Route Code/Leg:</td>
<td>{!! $flight->route_code ?: '-' !!}/{!! $flight->route_leg ?: '-' !!}</td>
<td>{{ $flight->route_code ?: '-' }}/{{ $flight->route_leg ?: '-' }}</td>
</tr>
<tr>
<td>Alternate Airport</td>
<td>
@if($flight->alt_airport_id)
{!! $flight->alt_airport->full_name !!}
{{ $flight->alt_airport->full_name }}
@else
-
@endif
@@ -39,12 +39,12 @@
<tr>
<td>Route</td>
<td>{!! $flight->route !!}</td>
<td>{{ $flight->route }}</td>
</tr>
<tr>
<td>Notes</td>
<td>{!! $flight->notes !!}</td>
<td>{{ $flight->notes }}</td>
</tr>
</table>
</div>
@@ -4,8 +4,8 @@
<div class="row">
<div class="col-sm-9">
<h5>
<a class="text-c" href="{!! route('frontend.flights.show', [$flight->id]) !!}">
{!! $flight->ident !!}
<a class="text-c" href="{{ route('frontend.flights.show', [$flight->id]) }}">
{{ $flight->ident }}
</a>
</h5>
</div>
@@ -20,7 +20,7 @@
<button class="btn btn-round btn-icon btn-icon-mini
{{ in_array($flight->id, $saved, true) ? 'btn-info':'' }}
save_flight"
x-id="{!! $flight->id !!}"
x-id="{{ $flight->id }}"
x-saved-class="btn-info"
type="button"
title="Add/Remove Bid"
@@ -32,26 +32,26 @@
<div class="row">
<div class="col-sm-5">
<span class="title">DEP&nbsp;</span>
{!! $flight->dpt_airport->icao !!}@if($flight->dpt_time), {!! $flight->dpt_time !!}@endif
{{ $flight->dpt_airport->icao }}@if($flight->dpt_time), {{ $flight->dpt_time }}@endif
<br />
<span class="title">ARR&nbsp;</span>
{!! $flight->arr_airport->icao !!}@if($flight->arr_time), {!! $flight->arr_time !!}@endif
{{ $flight->arr_airport->icao }}@if($flight->arr_time), {{ $flight->arr_time }}@endif
<br />
@if($flight->distance)
<span class="title">DISTANCE&nbsp;</span>
{!! $flight->distance !!} {!! setting('units.distance') !!}
{{ $flight->distance }} {{ setting('units.distance') }}
@endif
<br />
@if($flight->level)
<span class="title">LEVEL&nbsp;</span>
{!! $flight->level !!} {!! setting('units.altitude') !!}
{{ $flight->level }} {{ setting('units.altitude') }}
@endif
</div>
<div class="col-sm-7">
<div class="row">
<div class="col-sm-12">
<span class="title">ROUTE&nbsp;</span>
{!! $flight->route !!}
{{ $flight->route }}
</div>
</div>
</div>