[v8.2.x] Sanitized NavBar children links to remove angular interpolation (#41283)
* Sanitized nav bar links to remove angular interpolation * NavBar: Add sanitize to children items (cherry picked from commita3dc30546f) (cherry picked from commit561ca52ab3) * use replaceAll when sanitizing urls (cherry picked from commit8081dc9ee9) (cherry picked from commitc86d520821) * switch to global regexp (cherry picked from commit1c7ce348ce) (cherry picked from commit28e2be2a8a) * Resolve conflicts Co-authored-by: Alexandra Vargas <alexa1866@gmail.com> Co-authored-by: Dan Cech <dcech@grafana.com>
This commit is contained in:
co-authored by
Alexandra Vargas
Dan Cech
parent
120689b3c6
commit
d52f25825b
@@ -1,11 +1,12 @@
|
||||
export * from './string';
|
||||
export * from './markdown';
|
||||
export * from './text';
|
||||
import { escapeHtml, hasAnsiCodes, sanitize, sanitizeUrl } from './sanitize';
|
||||
import { escapeHtml, hasAnsiCodes, sanitize, sanitizeUrl, sanitizeAngularInterpolation } from './sanitize';
|
||||
|
||||
export const textUtil = {
|
||||
escapeHtml,
|
||||
hasAnsiCodes,
|
||||
sanitize,
|
||||
sanitizeUrl,
|
||||
sanitizeAngularInterpolation,
|
||||
};
|
||||
|
||||
@@ -38,3 +38,7 @@ export function hasAnsiCodes(input: string): boolean {
|
||||
export function escapeHtml(str: string): string {
|
||||
return String(str).replace(/&/g, '&').replace(/</g, '<').replace(/>/g, '>').replace(/"/g, '"');
|
||||
}
|
||||
|
||||
export function sanitizeAngularInterpolation(url: string): string {
|
||||
return url.replace(/\{\{/g, '%7B%7B').replace(/\}\}/g, '%7D%7D');
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user