Fixing XSS vulnerability by using the proper output tags
This commit is contained in:
@@ -6,11 +6,11 @@
|
||||
<div class="col-md-12">
|
||||
<h2 class="description">New Flight Report</h2>
|
||||
@include('flash::message')
|
||||
{!! Form::open(['route' => 'frontend.pireps.store']) !!}
|
||||
{{ Form::open(['route' => 'frontend.pireps.store']) }}
|
||||
|
||||
@include("pireps.fields")
|
||||
|
||||
{!! Form::close() !!}
|
||||
{{ Form::close() }}
|
||||
</div>
|
||||
</div>
|
||||
@endsection
|
||||
|
||||
@@ -5,11 +5,11 @@
|
||||
<div class="col-md-12">
|
||||
<h2 class="description">Edit Flight Report</h2>
|
||||
@include('flash::message')
|
||||
{!! Form::model($pirep, ['route' => ['frontend.pireps.update', $pirep->id], 'method' => 'patch']) !!}
|
||||
{{ Form::model($pirep, ['route' => ['frontend.pireps.update', $pirep->id], 'method' => 'patch']) }}
|
||||
|
||||
@include("pireps.fields")
|
||||
|
||||
{!! Form::close() !!}
|
||||
{{ Form::close() }}
|
||||
</div>
|
||||
</div>
|
||||
@endsection
|
||||
|
||||
@@ -9,14 +9,14 @@
|
||||
<tbody>
|
||||
@foreach($aircraft->subfleet->fares as $fare)
|
||||
<tr>
|
||||
<td style="text-align: right;">{!! $fare->name !!} ({!! $fare->code !!})</td>
|
||||
<td style="text-align: right;">{{ $fare->name }} ({{ $fare->code }})</td>
|
||||
<td>
|
||||
@if($read_only)
|
||||
<p>{!! $pirep->{'fare_'.$fare->id} !!}</p>
|
||||
{!! Form::hidden('fare_'.$fare->id) !!}
|
||||
<p>{{ $pirep->{'fare_'.$fare->id} }}</p>
|
||||
{{ Form::hidden('fare_'.$fare->id) }}
|
||||
@else
|
||||
<div class="input-group form-group">
|
||||
{!! Form::number('fare_'.$fare->id, null, ['class' => 'form-control', 'min' => 0]) !!}
|
||||
{{ Form::number('fare_'.$fare->id, null, ['class' => 'form-control', 'min' => 0]) }}
|
||||
</div>
|
||||
@endif
|
||||
</td>
|
||||
|
||||
@@ -28,13 +28,13 @@ flight reports that have been filed. You've been warned!
|
||||
<td>Airline</td>
|
||||
<td>
|
||||
@if($read_only)
|
||||
<p>{!! $pirep->airline->name !!}</p>
|
||||
{!! Form::hidden('airline_id') !!}
|
||||
<p>{{ $pirep->airline->name }}</p>
|
||||
{{ Form::hidden('airline_id') }}
|
||||
@else
|
||||
<div class="input-group form-group">
|
||||
{!! Form::select('airline_id', $airline_list, null, [
|
||||
{{ Form::select('airline_id', $airline_list, null, [
|
||||
'class' => 'custom-select select2',
|
||||
'readonly' => $read_only]) !!}
|
||||
'readonly' => $read_only]) }}
|
||||
</div>
|
||||
<p class="text-danger">{{ $errors->first('airline_id') }}</p>
|
||||
@endif
|
||||
@@ -45,27 +45,27 @@ flight reports that have been filed. You've been warned!
|
||||
<td>Flight Number/Code/Leg</td>
|
||||
<td>
|
||||
@if($read_only)
|
||||
<p>{!! $pirep->ident !!}
|
||||
{!! Form::hidden('flight_number') !!}
|
||||
{!! Form::hidden('flight_code') !!}
|
||||
{!! Form::hidden('flight_leg') !!}
|
||||
<p>{{ $pirep->ident }}
|
||||
{{ Form::hidden('flight_number') }}
|
||||
{{ Form::hidden('flight_code') }}
|
||||
{{ Form::hidden('flight_leg') }}
|
||||
</p>
|
||||
@else
|
||||
<div class="input-group form-group" style="max-width: 400px;">
|
||||
{!! Form::text('flight_number', null, [
|
||||
{{ Form::text('flight_number', null, [
|
||||
'placeholder' => 'Flight Number',
|
||||
'class' => 'form-control',
|
||||
'readonly' => $read_only]) !!}
|
||||
'readonly' => $read_only]) }}
|
||||
|
||||
{!! Form::text('route_code', null, [
|
||||
{{ Form::text('route_code', null, [
|
||||
'placeholder' => 'Code (optional)',
|
||||
'class' => 'form-control',
|
||||
'readonly' => $read_only]) !!}
|
||||
'readonly' => $read_only]) }}
|
||||
|
||||
{!! Form::text('route_leg', null, [
|
||||
{{ Form::text('route_leg', null, [
|
||||
'placeholder' => 'Leg (optional)',
|
||||
'class' => 'form-control',
|
||||
'readonly' => $read_only]) !!}
|
||||
'readonly' => $read_only]) }}
|
||||
</div>
|
||||
<p class="text-danger">{{ $errors->first('flight_number') }}</p>
|
||||
<p class="text-danger">{{ $errors->first('route_code') }}</p>
|
||||
@@ -78,16 +78,16 @@ flight reports that have been filed. You've been warned!
|
||||
<td>Aircraft</td>
|
||||
<td>
|
||||
@if($read_only)
|
||||
<p>{!! $pirep->aircraft->name !!}</p>
|
||||
{!! Form::hidden('aircraft_id') !!}
|
||||
<p>{{ $pirep->aircraft->name }}</p>
|
||||
{{ Form::hidden('aircraft_id') }}
|
||||
@else
|
||||
<div class="input-group form-group">
|
||||
{{-- You probably don't want to change this ID if you want the fare select to work --}}
|
||||
{!! Form::select('aircraft_id', $aircraft_list, null, [
|
||||
{{ Form::select('aircraft_id', $aircraft_list, null, [
|
||||
'id' => 'aircraft_select',
|
||||
'class' => 'custom-select select2',
|
||||
'readonly' => $read_only
|
||||
]) !!}
|
||||
]) }}
|
||||
</div>
|
||||
<p class="text-danger">{{ $errors->first('aircraft_id') }}</p>
|
||||
@endif
|
||||
@@ -98,14 +98,14 @@ flight reports that have been filed. You've been warned!
|
||||
<td>Origin Airport</td>
|
||||
<td>
|
||||
@if($read_only)
|
||||
<p>{!! $pirep->dpt_airport->id !!} - {!! $pirep->dpt_airport->name !!}</p>
|
||||
{!! Form::hidden('dpt_airport_id') !!}
|
||||
<p>{{ $pirep->dpt_airport->id }} - {{ $pirep->dpt_airport->name }}</p>
|
||||
{{ Form::hidden('dpt_airport_id') }}
|
||||
@else
|
||||
<div class="input-group form-group">
|
||||
{!! Form::select('dpt_airport_id', $airport_list, null, [
|
||||
{{ Form::select('dpt_airport_id', $airport_list, null, [
|
||||
'class' => 'custom-select select2',
|
||||
'readonly' => $read_only
|
||||
]) !!}
|
||||
]) }}
|
||||
</div>
|
||||
<p class="text-danger">{{ $errors->first('dpt_airport_id') }}</p>
|
||||
@endif
|
||||
@@ -116,15 +116,15 @@ flight reports that have been filed. You've been warned!
|
||||
<td>Arrival Airport</td>
|
||||
<td>
|
||||
@if($read_only)
|
||||
<p>{!! $pirep->arr_airport->id !!}
|
||||
- {!! $pirep->arr_airport->name !!}</p>
|
||||
{!! Form::hidden('arr_airport_id') !!}
|
||||
<p>{{ $pirep->arr_airport->id }}
|
||||
- {{ $pirep->arr_airport->name }}</p>
|
||||
{{ Form::hidden('arr_airport_id') }}
|
||||
@else
|
||||
<div class="input-group form-group">
|
||||
{!! Form::select('arr_airport_id', $airport_list, null, [
|
||||
{{ Form::select('arr_airport_id', $airport_list, null, [
|
||||
'class' => 'custom-select select2',
|
||||
'readonly' => $read_only
|
||||
]) !!}
|
||||
]) }}
|
||||
</div>
|
||||
<p class="text-danger">{{ $errors->first('arr_airport_id') }}</p>
|
||||
@endif
|
||||
@@ -136,25 +136,25 @@ flight reports that have been filed. You've been warned!
|
||||
<td>
|
||||
@if($read_only)
|
||||
<p>
|
||||
{!! $pirep->hours !!} hours, {!! $pirep->minutes !!} minutes
|
||||
{!! Form::hidden('hours') !!}
|
||||
{!! Form::hidden('minutes') !!}
|
||||
{{ $pirep->hours }} hours, {{ $pirep->minutes }} minutes
|
||||
{{ Form::hidden('hours') }}
|
||||
{{ Form::hidden('minutes') }}
|
||||
</p>
|
||||
@else
|
||||
<div class="input-group" style="max-width: 200px;">
|
||||
{!! Form::number('hours', null, [
|
||||
{{ Form::number('hours', null, [
|
||||
'class' => 'form-control',
|
||||
'placeholder' => 'hours',
|
||||
'min' => '0',
|
||||
'readonly' => $read_only
|
||||
]) !!}
|
||||
]) }}
|
||||
|
||||
{!! Form::number('minutes', null, [
|
||||
{{ Form::number('minutes', null, [
|
||||
'class' => 'form-control',
|
||||
'placeholder' => 'minutes',
|
||||
'min' => 0,
|
||||
'readonly' => $read_only
|
||||
]) !!}
|
||||
]) }}
|
||||
</div>
|
||||
<p class="text-danger">{{ $errors->first('hours') }}</p>
|
||||
<p class="text-danger">{{ $errors->first('minutes') }}</p>
|
||||
@@ -168,16 +168,16 @@ flight reports that have been filed. You've been warned!
|
||||
@foreach($pirep_fields as $field)
|
||||
<tr>
|
||||
<td>
|
||||
{!! $field->name !!}
|
||||
{{ $field->name }}
|
||||
@if($field->required === true)
|
||||
<span class="text-danger">*</span>
|
||||
@endif
|
||||
</td>
|
||||
<td>
|
||||
<div class="input-group form-group">
|
||||
{!! Form::text($field->slug, null, [
|
||||
{{ Form::text($field->slug, null, [
|
||||
'class' => 'form-control'
|
||||
]) !!}
|
||||
]) }}
|
||||
</div>
|
||||
<p class="text-danger">{{ $errors->first($field->slug) }}</p>
|
||||
</td>
|
||||
@@ -188,7 +188,7 @@ flight reports that have been filed. You've been warned!
|
||||
<td class="align-text-top">Route</td>
|
||||
<td>
|
||||
<div class="input-group form-group">
|
||||
{!! Form::textarea('route', null, ['class' => 'form-control', 'placeholder' => 'Route']) !!}
|
||||
{{ Form::textarea('route', null, ['class' => 'form-control', 'placeholder' => 'Route']) }}
|
||||
</div>
|
||||
<p class="text-danger">{{ $errors->first('route') }}</p>
|
||||
</td>
|
||||
@@ -198,7 +198,7 @@ flight reports that have been filed. You've been warned!
|
||||
<td class="align-text-top"><p class="">Notes</p></td>
|
||||
<td>
|
||||
<div class="input-group form-group">
|
||||
{!! Form::textarea('notes', null, ['class' => 'form-control', 'placeholder' => 'Notes']) !!}
|
||||
{{ Form::textarea('notes', null, ['class' => 'form-control', 'placeholder' => 'Notes']) }}
|
||||
</div>
|
||||
<p class="text-danger">{{ $errors->first('notes') }}</p>
|
||||
</td>
|
||||
@@ -218,7 +218,7 @@ flight reports that have been filed. You've been warned!
|
||||
<div class="col-sm-12">
|
||||
<div class="float-right">
|
||||
<div class="form-group">
|
||||
{!! Form::submit('Save PIREP', ['class' => 'btn btn-primary']) !!}
|
||||
{{ Form::submit('Save PIREP', ['class' => 'btn btn-primary']) }}
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
@@ -7,7 +7,7 @@
|
||||
<div style="float:right;">
|
||||
<a class="btn btn-primary pull-right btn-lg"
|
||||
style="margin-top: -10px;margin-bottom: 5px"
|
||||
href="{!! route('frontend.pireps.create') !!}">File New PIREP</a>
|
||||
href="{{ route('frontend.pireps.create') }}">File New PIREP</a>
|
||||
</div>
|
||||
<h2 class="description">pilot reports</h2>
|
||||
@include('flash::message')
|
||||
|
||||
@@ -12,10 +12,10 @@
|
||||
@section('scripts')
|
||||
<script type="text/javascript">
|
||||
phpvms.map.render_route_map({
|
||||
route_points: {!! json_encode($map_features['planned_rte_points']) !!},
|
||||
planned_route_line: {!! json_encode($map_features['planned_rte_line']); !!},
|
||||
actual_route_line: {!! json_encode($map_features['actual_route_line']); !!},
|
||||
actual_route_points: {!! json_encode($map_features['actual_route_points']); !!},
|
||||
route_points: {{ json_encode($map_features['planned_rte_points']) }},
|
||||
planned_route_line: {{ json_encode($map_features['planned_rte_line']) }},
|
||||
actual_route_line: {{ json_encode($map_features['actual_route_line']) }},
|
||||
actual_route_points: {{ json_encode($map_features['actual_route_points']) }},
|
||||
});
|
||||
</script>
|
||||
@endsection
|
||||
|
||||
@@ -3,8 +3,8 @@
|
||||
<div class="row">
|
||||
<div class="col-sm-2 text-center">
|
||||
<h5>
|
||||
<a class="text-c" href="{!! route('frontend.pireps.show', [$pirep->id]) !!}">
|
||||
{!! $pirep->ident !!}
|
||||
<a class="text-c" href="{{ route('frontend.pireps.show', [$pirep->id]) }}">
|
||||
{{ $pirep->ident }}
|
||||
</a>
|
||||
</h5>
|
||||
<div>
|
||||
@@ -17,7 +17,7 @@
|
||||
@else
|
||||
<div class="badge badge-info">
|
||||
@endif
|
||||
{!! PirepState::label($pirep->state) !!}</div>
|
||||
{{ PirepState::label($pirep->state) }}</div>
|
||||
</div>
|
||||
</div>
|
||||
<div class="col-sm-10">
|
||||
@@ -26,36 +26,36 @@
|
||||
<table width="100%">
|
||||
<tr>
|
||||
<td width="20%" nowrap><span class="title">DEP </span></td>
|
||||
<td>{!! $pirep->dpt_airport_id !!}</td>
|
||||
<td>{{ $pirep->dpt_airport_id }}</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td nowrap><span class="title">ARR </span></td>
|
||||
<td>{!! $pirep->arr_airport_id !!} </td>
|
||||
<td>{{ $pirep->arr_airport_id }} </td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td nowrap><span class="title">Flight Time </span></td>
|
||||
<td>{!! Utils::minutesToTimeString($pirep->flight_time) !!}</td>
|
||||
<td>{{ Utils::minutesToTimeString($pirep->flight_time) }}</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td nowrap><span class="title">Aircraft </span></td>
|
||||
<td>{!! $pirep->aircraft->name !!}
|
||||
({!! $pirep->aircraft->registration !!})</td>
|
||||
<td>{{ $pirep->aircraft->name }}
|
||||
({{ $pirep->aircraft->registration }})</td>
|
||||
</tr>
|
||||
@if($pirep->level)
|
||||
<tr>
|
||||
<td nowrap><span class="title">Flight Level </span></td>
|
||||
<td>{!! $pirep->level !!}</td>
|
||||
<td>{{ $pirep->level }}</td>
|
||||
</tr>
|
||||
@endif
|
||||
<tr>
|
||||
<td nowrap><span class="title">Filed On: </span></td>
|
||||
<td>{!! show_datetime($pirep->created_at) !!}</td>
|
||||
<td>{{ show_datetime($pirep->created_at) }}</td>
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<div class="col-sm-6">
|
||||
<p style="text-align: right;">
|
||||
<a href="{!! route('frontend.pireps.edit', ['id'=>$pirep->id]) !!}">edit</a>
|
||||
<a href="{{ route('frontend.pireps.edit', ['id'=>$pirep->id]) }}">edit</a>
|
||||
</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
@@ -9,10 +9,10 @@
|
||||
console.log('aircraft select change: ', aircraft_id);
|
||||
|
||||
$.ajax({
|
||||
url: "{!! url('/pireps/fares') !!}?aircraft_id=" + aircraft_id,
|
||||
url: "{{ url('/pireps/fares') }}?aircraft_id=" + aircraft_id,
|
||||
type: 'GET',
|
||||
headers: {
|
||||
'x-api-key': '{!! Auth::user()->api_key !!}'
|
||||
'x-api-key': '{{ Auth::user()->api_key }}'
|
||||
},
|
||||
success: (data) => {
|
||||
console.log('returned new fares', data);
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
@section('content')
|
||||
<div class="row">
|
||||
<div class="col-md-12">
|
||||
<h2 class="description">{!! $pirep->ident !!}</h2>
|
||||
<h2 class="description">{{ $pirep->ident }}</h2>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
@@ -24,47 +24,47 @@
|
||||
<div class="badge badge-info">
|
||||
@endif
|
||||
|
||||
{!! PirepState::label($pirep->state) !!}</div>
|
||||
{{ PirepState::label($pirep->state) }}</div>
|
||||
|
||||
<span class="description" style="padding-left: 20px;">
|
||||
source: {!! PirepSource::label($pirep->source) !!}
|
||||
source: {{ PirepSource::label($pirep->source) }}
|
||||
</span>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Departure/Arrival</td>
|
||||
<td>
|
||||
{!! $pirep->dpt_airport->icao !!} - {!! $pirep->dpt_airport->name !!}
|
||||
{{ $pirep->dpt_airport->icao }} - {{ $pirep->dpt_airport->name }}
|
||||
<span class="description">to</span>
|
||||
{!! $pirep->arr_airport->icao !!} - {!! $pirep->arr_airport->name !!}
|
||||
{{ $pirep->arr_airport->icao }} - {{ $pirep->arr_airport->name }}
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr>
|
||||
<td>Flight Time</td>
|
||||
<td>
|
||||
{!! Utils::minutesToTimeString($pirep->flight_time) !!}
|
||||
{{ Utils::minutesToTimeString($pirep->flight_time) }}
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr>
|
||||
<td>Filed Route</td>
|
||||
<td>
|
||||
{!! $pirep->route !!}
|
||||
{{ $pirep->route }}
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr>
|
||||
<td>Notes</td>
|
||||
<td>
|
||||
{!! $pirep->notes !!}
|
||||
{{ $pirep->notes }}
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr>
|
||||
<td>Filed On</td>
|
||||
<td>
|
||||
{!! show_datetime($pirep->created_at) !!}
|
||||
{{ show_datetime($pirep->created_at) }}
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
@@ -88,8 +88,8 @@
|
||||
<tbody>
|
||||
@foreach($pirep->fields as $field)
|
||||
<tr>
|
||||
<td>{!! $field->name !!}</td>
|
||||
<td>{!! $field->value !!}</td>
|
||||
<td>{{ $field->name }}</td>
|
||||
<td>{{ $field->value }}</td>
|
||||
</tr>
|
||||
@endforeach
|
||||
</tbody>
|
||||
@@ -114,8 +114,8 @@
|
||||
<tbody>
|
||||
@foreach($pirep->fares as $fare)
|
||||
<tr>
|
||||
<td>{!! $fare->fare->name !!} ({!! $fare->fare->code !!})</td>
|
||||
<td>{!! $fare->count !!}</td>
|
||||
<td>{{ $fare->fare->name }} ({{ $fare->fare->code }})</td>
|
||||
<td>{{ $fare->count }}</td>
|
||||
</tr>
|
||||
@endforeach
|
||||
</tbody>
|
||||
@@ -137,8 +137,8 @@
|
||||
<tbody>
|
||||
@foreach($pirep->acars_logs as $log)
|
||||
<tr>
|
||||
<td nowrap="true">{!! show_datetime($log->created_at) !!}</td>
|
||||
<td>{!! $log->log !!}</td>
|
||||
<td nowrap="true">{{ show_datetime($log->created_at) }}</td>
|
||||
<td>{{ $log->log }}</td>
|
||||
</tr>
|
||||
@endforeach
|
||||
</tbody>
|
||||
|
||||
Reference in New Issue
Block a user