Add htmlentities to protect nick/addr in acl_lookup
parent
96b1a00e91
commit
bffd3f2304
|
@ -639,13 +639,13 @@ function acl_lookup(App $a, $out_type = 'json') {
|
||||||
|
|
||||||
if (count($contact) > 0) {
|
if (count($contact) > 0) {
|
||||||
$unknown_contacts[] = array(
|
$unknown_contacts[] = array(
|
||||||
'type' => 'cu',
|
'type' => 'c',
|
||||||
'photo' => proxy_url($contact['micro'], false, PROXY_SIZE_MICRO),
|
'photo' => proxy_url($contact['micro'], false, PROXY_SIZE_MICRO),
|
||||||
'name' => htmlentities($contact['name']),
|
'name' => htmlentities($contact['name']),
|
||||||
'id' => intval($contact['cid']),
|
'id' => intval($contact['cid']),
|
||||||
'network' => $contact['network'],
|
'network' => $contact['network'],
|
||||||
'link' => $contact['url'],
|
'link' => $contact['url'],
|
||||||
'nick' => $contact['nick'] ? : $contact['addr'],
|
'nick' => htmlentities($contact['nick'] ? : $contact['addr']),
|
||||||
'forum' => $contact['forum']
|
'forum' => $contact['forum']
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
Loading…
Reference in New Issue