From 77c510c3647829a674bc5e48391026a5da375576 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Torkel=20=C3=96degaard?= Date: Thu, 10 Dec 2015 13:27:57 +0100 Subject: [PATCH] fix(graph legend): fixed issue with escaping html text in graph legend, and in function param, fixes #3482 --- public/app/features/templating/templateSrv.js | 1 + public/app/panels/graph/legend.js | 2 +- 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/public/app/features/templating/templateSrv.js b/public/app/features/templating/templateSrv.js index 9a59510c6a4..267454dbecb 100644 --- a/public/app/features/templating/templateSrv.js +++ b/public/app/features/templating/templateSrv.js @@ -79,6 +79,7 @@ function (angular, _) { this.highlightVariablesAsHtml = function(str) { if (!str || !_.isString(str)) { return str; } + str = _.escape(str); this._regex.lastIndex = 0; return str.replace(this._regex, function(match, g1, g2) { if (self._values[g1 || g2]) { diff --git a/public/app/panels/graph/legend.js b/public/app/panels/graph/legend.js index 8604dff4f08..b3e1a998ccb 100644 --- a/public/app/panels/graph/legend.js +++ b/public/app/panels/graph/legend.js @@ -151,7 +151,7 @@ function (angular, _, $) { html += ''; html += '
'; - html += '' + series.label + ''; + html += '' + _.escape(series.label) + ''; html += '
'; if (panel.legend.values) {