Merge pull request #3373 from overleaf/jpa-block-recurly-xss

[views] subscription: block angular template evaluation for emails

GitOrigin-RevId: 081314a387234dfe263b954a4206a0c8bba8b153
This commit is contained in:
Simon Detheridge 2020-11-09 10:35:01 +00:00 committed by Copybot
parent f848e65a40
commit 8e20258786

View file

@ -8,7 +8,7 @@
.alert.alert-success(ng-show="updateAccountEmailAddress.response.success")
| #{translate('recurly_email_updated')}
div(ng-hide="updateAccountEmailAddress.response.success")
p !{translate("recurly_email_update_needed", { recurlyEmail: personalSubscription.recurly.account.email, userEmail: user.email }, ['em', 'em'])}
p(ng-non-bindable) !{translate("recurly_email_update_needed", { recurlyEmail: personalSubscription.recurly.account.email, userEmail: user.email }, ['em', 'em'])}
.actions
button.btn-primary.btn(
type='submit',