Fixed security issue #182
This commit is contained in:
parent
13e43e2b25
commit
05dbc03a0b
|
@ -185,7 +185,7 @@ var ContactList = (function (my) {
|
|||
*/
|
||||
function createDisplayNameParagraph(displayName) {
|
||||
var p = document.createElement('p');
|
||||
p.innerHTML = displayName;
|
||||
p.innerText = displayName;
|
||||
|
||||
return p;
|
||||
};
|
||||
|
@ -203,7 +203,7 @@ var ContactList = (function (my) {
|
|||
var contactName = $('#contactlist #' + resourceJid + '>p');
|
||||
|
||||
if (contactName && displayName && displayName.length > 0)
|
||||
contactName.html(displayName);
|
||||
contactName.text(displayName);
|
||||
});
|
||||
|
||||
my.setClickable = function(resourceJid, isClickable) {
|
||||
|
|
Loading…
Reference in New Issue