[v8.2.x] Sanitized NavBar children links to remove angular interpolation (#41283)

* Sanitized nav bar links to remove angular interpolation

* NavBar: Add sanitize to children items

(cherry picked from commit a3dc30546f)
(cherry picked from commit 561ca52ab3)

* use replaceAll when sanitizing urls

(cherry picked from commit 8081dc9ee9)
(cherry picked from commit c86d520821)

* switch to global regexp

(cherry picked from commit 1c7ce348ce)
(cherry picked from commit 28e2be2a8a)

* Resolve conflicts

Co-authored-by: Alexandra Vargas <alexa1866@gmail.com>
Co-authored-by: Dan Cech <dcech@grafana.com>
This commit is contained in:
Dimitris Sotirakis
2021-11-03 17:05:29 +01:00
committed by GitHub
co-authored by Alexandra Vargas Dan Cech
parent 120689b3c6
commit d52f25825b
4 changed files with 17 additions and 9 deletions
+2 -1
View File
@@ -1,11 +1,12 @@
export * from './string';
export * from './markdown';
export * from './text';
import { escapeHtml, hasAnsiCodes, sanitize, sanitizeUrl } from './sanitize';
import { escapeHtml, hasAnsiCodes, sanitize, sanitizeUrl, sanitizeAngularInterpolation } from './sanitize';
export const textUtil = {
escapeHtml,
hasAnsiCodes,
sanitize,
sanitizeUrl,
sanitizeAngularInterpolation,
};
@@ -38,3 +38,7 @@ export function hasAnsiCodes(input: string): boolean {
export function escapeHtml(str: string): string {
return String(str).replace(/&/g, '&amp;').replace(/</g, '&lt;').replace(/>/g, '&gt;').replace(/"/g, '&quot;');
}
export function sanitizeAngularInterpolation(url: string): string {
return url.replace(/\{\{/g, '%7B%7B').replace(/\}\}/g, '%7D%7D');
}