Fixing XSS vulnerability by using the proper output tags
This commit is contained in:
@@ -6,9 +6,9 @@
|
||||
<div class="col-md-12">
|
||||
<h2 class="description">edit your profile</h2>
|
||||
@include('flash::message')
|
||||
{!! Form::model($user, ['route' => ['frontend.profile.update', $user->id], 'method' => 'patch']) !!}
|
||||
{{ Form::model($user, ['route' => ['frontend.profile.update', $user->id], 'method' => 'patch']) }}
|
||||
@include("profile.fields")
|
||||
{!! Form::close() !!}
|
||||
{{ Form::close() }}
|
||||
</div>
|
||||
</div>
|
||||
@endsection
|
||||
|
||||
@@ -5,7 +5,7 @@
|
||||
<td>Name</td>
|
||||
<td>
|
||||
<div class="input-group form-group-no-border{{ $errors->has('name') ? ' has-danger' : '' }}">
|
||||
{!! Form::text('name', null, ['class' => 'form-control']) !!}
|
||||
{{ Form::text('name', null, ['class' => 'form-control']) }}
|
||||
</div>
|
||||
@if ($errors->has('name'))
|
||||
<p class="text-danger">{{ $errors->first('name') }}</p>
|
||||
@@ -17,7 +17,7 @@
|
||||
<td>Email</td>
|
||||
<td>
|
||||
<div class="input-group form-group-no-border{{ $errors->has('email') ? ' has-danger' : '' }}">
|
||||
{!! Form::text('email', null, ['class' => 'form-control']) !!}
|
||||
{{ Form::text('email', null, ['class' => 'form-control']) }}
|
||||
</div>
|
||||
@if ($errors->has('email'))
|
||||
<p class="text-danger">{{ $errors->first('email') }}</p>
|
||||
@@ -29,7 +29,7 @@
|
||||
<td>Airline</td>
|
||||
<td>
|
||||
<div class="input-group form-group-no-border{{ $errors->has('airline') ? ' has-danger' : '' }}">
|
||||
{!! Form::select('airline_id', $airlines, null , ['class' => 'form-control select2']) !!}
|
||||
{{ Form::select('airline_id', $airlines, null , ['class' => 'form-control select2']) }}
|
||||
</div>
|
||||
@if ($errors->has('airline_id'))
|
||||
<p class="text-danger">{{ $errors->first('airline_id') }}</p>
|
||||
@@ -41,7 +41,7 @@
|
||||
<td>Home Airport</td>
|
||||
<td>
|
||||
<div class="input-group form-group-no-border{{ $errors->has('home_airport_id') ? ' has-danger' : '' }}">
|
||||
{!! Form::select('home_airport_id', $airports, null , ['class' => 'form-control select2']) !!}
|
||||
{{ Form::select('home_airport_id', $airports, null , ['class' => 'form-control select2']) }}
|
||||
</div>
|
||||
@if ($errors->has('home_airport_id'))
|
||||
<p class="text-danger">{{ $errors->first('home_airport_id') }}</p>
|
||||
@@ -53,7 +53,7 @@
|
||||
<td>Country</td>
|
||||
<td>
|
||||
<div class="input-group form-group-no-border{{ $errors->has('country') ? ' has-danger' : '' }}">
|
||||
{!! Form::select('country', $countries, null, ['class' => 'form-control select2' ]); !!}
|
||||
{{ Form::select('country', $countries, null, ['class' => 'form-control select2' ]) }}
|
||||
</div>
|
||||
@if ($errors->has('country'))
|
||||
<p class="text-danger">{{ $errors->first('country') }}</p>
|
||||
@@ -65,7 +65,7 @@
|
||||
<td>Timezone</td>
|
||||
<td>
|
||||
<div class="input-group form-group-no-border{{ $errors->has('timezone') ? ' has-danger' : '' }}">
|
||||
{!! Form::select('timezone', $timezones, null, ['class' => 'form-control select2' ]); !!}
|
||||
{{ Form::select('timezone', $timezones, null, ['class' => 'form-control select2' ]) }}
|
||||
</div>
|
||||
@if ($errors->has('timezone'))
|
||||
<p class="text-danger">{{ $errors->first('timezone') }}</p>
|
||||
@@ -77,7 +77,7 @@
|
||||
<td>Change Password</td>
|
||||
<td>
|
||||
<div class="input-group form-group-no-border{{ $errors->has('password') ? ' has-danger' : '' }}">
|
||||
{!! Form::password('password', ['class' => 'form-control']) !!}
|
||||
{{ Form::password('password', ['class' => 'form-control']) }}
|
||||
</div>
|
||||
@if ($errors->has('password'))
|
||||
<p class="text-danger">{{ $errors->first('password') }}</p>
|
||||
@@ -85,7 +85,7 @@
|
||||
|
||||
<p>Confirm Password:</p>
|
||||
<div class="input-group form-group-no-border{{ $errors->has('password_confirmation') ? ' has-danger' : '' }}">
|
||||
{!! Form::password('password_confirmation', ['class' => 'form-control']) !!}
|
||||
{{ Form::password('password_confirmation', ['class' => 'form-control']) }}
|
||||
</div>
|
||||
@if ($errors->has('password_confirmation'))
|
||||
<p class="text-danger">{{ $errors->first('password_confirmation') }}</p>
|
||||
@@ -96,7 +96,7 @@
|
||||
</table>
|
||||
|
||||
<div style="width: 100%; text-align: right; padding-top: 20px;">
|
||||
{!! Form::submit('Update Profile', ['class' => 'btn btn-primary']) !!}
|
||||
{{ Form::submit('Update Profile', ['class' => 'btn btn-primary']) }}
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
@@ -5,38 +5,38 @@
|
||||
<div class="row profile-page content-center text-color-dark-beige">
|
||||
<div class="col-md-4" style="text-align:center;">
|
||||
<div class="photo-container">
|
||||
<img src="{!! $user->gravatar(512) !!}" style="width: 123px;">
|
||||
<img src="{{ $user->gravatar(512) }}" style="width: 123px;">
|
||||
</div>
|
||||
<h3 class="title">{!! $user->name !!}</h3>
|
||||
<h6><span class="flag-icon flag-icon-{!! $user->country !!}"></span></h6>
|
||||
<h6>{!! $user->pilot_id !!}</h6>
|
||||
<h6>{!! $user->rank->name !!}</h6>
|
||||
<h3 class="title">{{ $user->name }}</h3>
|
||||
<h6><span class="flag-icon flag-icon-{{ $user->country }}"></span></h6>
|
||||
<h6>{{ $user->pilot_id }}</h6>
|
||||
<h6>{{ $user->rank->name }}</h6>
|
||||
<p class="description" style="color: #9A9A9A;">
|
||||
{!! $user->airline->name !!}
|
||||
{{ $user->airline->name }}
|
||||
</p>
|
||||
</div>
|
||||
<div class="col-md-8 content-center">
|
||||
<div class="content">
|
||||
<div class="social-description">
|
||||
<h2>{!! $user->flights!!}</h2>
|
||||
<h2>{{ $user->flights}}</h2>
|
||||
<p>Flights</p>
|
||||
</div>
|
||||
|
||||
<div class="social-description">
|
||||
<h2>{!! \App\Facades\Utils::minutesToTimeString($user->flight_time, false) !!}</h2>
|
||||
<h2>{{ \App\Facades\Utils::minutesToTimeString($user->flight_time, false) }}</h2>
|
||||
<p>Flight Hours</p>
|
||||
</div>
|
||||
|
||||
@if($user->home_airport)
|
||||
<div class="social-description">
|
||||
<h2>{!! $user->home_airport->icao !!}</h2>
|
||||
<h2>{{ $user->home_airport->icao }}</h2>
|
||||
<p>Home Airport</p>
|
||||
</div>
|
||||
@endif
|
||||
|
||||
@if($user->current_airport)
|
||||
<div class="social-description">
|
||||
<h2>{!! $user->current_airport->icao !!}</h2>
|
||||
<h2>{{ $user->current_airport->icao }}</h2>
|
||||
<p>Current Airport</p>
|
||||
</div>
|
||||
@endif
|
||||
@@ -53,10 +53,10 @@
|
||||
<div class="row">
|
||||
<div class="col-sm-12">
|
||||
<div class="text-right">
|
||||
<a href="{!! route('frontend.profile.regen_apikey') !!}" class="btn btn-warning"
|
||||
<a href="{{ route('frontend.profile.regen_apikey') }}" class="btn btn-warning"
|
||||
onclick="return confirm('Are you sure? This will reset your API key.')">new api key</a>
|
||||
|
||||
<a href="{!! route('frontend.profile.edit', ['id' => $user->id]) !!}"
|
||||
<a href="{{ route('frontend.profile.edit', ['id' => $user->id]) }}"
|
||||
class="btn btn-primary">edit</a>
|
||||
</div>
|
||||
|
||||
@@ -64,15 +64,15 @@
|
||||
<table class="table table-full-width">
|
||||
<tr>
|
||||
<td>Email</td>
|
||||
<td>{!! $user->email !!}</td>
|
||||
<td>{{ $user->email }}</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>API Key <span class="description">don't share this!</span></td>
|
||||
<td>{!! $user->api_key !!}</td>
|
||||
<td>{{ $user->api_key }}</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Timezone</td>
|
||||
<td>{!! $user->timezone !!}</td>
|
||||
<td>{{ $user->timezone }}</td>
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
|
||||
Reference in New Issue
Block a user