Fix issue #1866, XSS in content types from schema.

This commit is contained in:
joev
2016-01-12 23:08:45 -06:00
parent 3abf8d2c0d
commit 50c713a261
5 changed files with 25 additions and 25 deletions

30
dist/swagger-ui.js vendored
View File

@@ -21,12 +21,12 @@ this["Handlebars"]["templates"]["content_type"] = Handlebars.template({"1":funct
if (stack1 != null) { buffer += stack1; }
return buffer;
},"2":function(depth0,helpers,partials,data) {
var stack1, lambda=this.lambda, escapeExpression=this.escapeExpression, buffer = " <option value=\""
var lambda=this.lambda, escapeExpression=this.escapeExpression;
return " <option value=\""
+ escapeExpression(lambda(depth0, depth0))
+ "\">";
stack1 = lambda(depth0, depth0);
if (stack1 != null) { buffer += stack1; }
return buffer + "</option>\n";
+ "\">"
+ escapeExpression(lambda(depth0, depth0))
+ "</option>\n";
},"4":function(depth0,helpers,partials,data) {
return " <option value=\"application/json\">application/json</option>\n";
},"compiler":[6,">= 2.0.0-beta.1"],"main":function(depth0,helpers,partials,data) {
@@ -801,12 +801,12 @@ this["Handlebars"]["templates"]["parameter_content_type"] = Handlebars.template(
if (stack1 != null) { buffer += stack1; }
return buffer;
},"2":function(depth0,helpers,partials,data) {
var stack1, lambda=this.lambda, escapeExpression=this.escapeExpression, buffer = " <option value=\""
var lambda=this.lambda, escapeExpression=this.escapeExpression;
return " <option value=\""
+ escapeExpression(lambda(depth0, depth0))
+ "\">";
stack1 = lambda(depth0, depth0);
if (stack1 != null) { buffer += stack1; }
return buffer + "</option>\n";
+ "\">"
+ escapeExpression(lambda(depth0, depth0))
+ "</option>\n";
},"4":function(depth0,helpers,partials,data) {
return " <option value=\"application/json\">application/json</option>\n";
},"compiler":[6,">= 2.0.0-beta.1"],"main":function(depth0,helpers,partials,data) {
@@ -862,12 +862,12 @@ this["Handlebars"]["templates"]["response_content_type"] = Handlebars.template({
if (stack1 != null) { buffer += stack1; }
return buffer;
},"2":function(depth0,helpers,partials,data) {
var stack1, lambda=this.lambda, escapeExpression=this.escapeExpression, buffer = " <option value=\""
var lambda=this.lambda, escapeExpression=this.escapeExpression;
return " <option value=\""
+ escapeExpression(lambda(depth0, depth0))
+ "\">";
stack1 = lambda(depth0, depth0);
if (stack1 != null) { buffer += stack1; }
return buffer + "</option>\n";
+ "\">"
+ escapeExpression(lambda(depth0, depth0))
+ "</option>\n";
},"4":function(depth0,helpers,partials,data) {
return " <option value=\"application/json\">application/json</option>\n";
},"compiler":[6,">= 2.0.0-beta.1"],"main":function(depth0,helpers,partials,data) {