Merge pull request #3722 from overleaf/as-fix-project-invite-xss

Prevent stored XSS on project invite page

GitOrigin-RevId: ada89c46d62e64d794edacc9be3c08b622ce433c
This commit is contained in:
Alf Eaton 2021-03-04 11:31:30 +00:00 committed by Copybot
parent 248e860757
commit 869bdf89e0

View file

@ -7,7 +7,7 @@ block content
.col-md-8.col-md-offset-2
.card.project-invite-accept
.page-header.text-centered
h1 #{translate("user_wants_you_to_see_project", {username:owner.first_name, projectname:""})}
h1(ng-non-bindable) #{translate("user_wants_you_to_see_project", {username:owner.first_name, projectname:""})}
br
em(ng-non-bindable) #{project.name}
.row.text-center