From 91594eee6d8596670ab966d03f8d072ba6e53689 Mon Sep 17 00:00:00 2001 From: Chrystal Maria Griffiths Date: Mon, 4 Feb 2019 11:14:44 +0000 Subject: [PATCH] Merge pull request #1473 from sharelatex/as-fix-notification-translation Inject data into translation string to workaround removed potential XSS GitOrigin-RevId: 6d9fa7050dafa1d48e3622765586eb4350dc514b --- services/web/app/views/project/list/notifications.pug | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/services/web/app/views/project/list/notifications.pug b/services/web/app/views/project/list/notifications.pug index ac503da9ab..243fefae94 100644 --- a/services/web/app/views/project/list/notifications.pug +++ b/services/web/app/views/project/list/notifications.pug @@ -12,7 +12,7 @@ span(ng-controller="NotificationsController").userNotifications .alert.alert-info(ng-switch-when="notification_project_invite", ng-controller="ProjectInviteNotificationController") div.notification_inner .notification_body(ng-show="!notification.accepted") - | !{translate("notification_project_invite_message")} + | !{translate("notification_project_invite_message", { userName: "{{ userName }}" })} a.pull-right.btn.btn-sm.btn-info(href, ng-click="accept()", ng-disabled="notification.inflight") span(ng-show="!notification.inflight") #{translate("join_project")} span(ng-show="notification.inflight") @@ -20,7 +20,7 @@ span(ng-controller="NotificationsController").userNotifications |   | #{translate("joining")}... .notification_body(ng-show="notification.accepted") - | !{translate("notification_project_invite_accepted_message")} + | !{translate("notification_project_invite_accepted_message", { projectName: "{{ projectName }}" })} a.pull-right.btn.btn-sm.btn-info(href="/project/{{ notification.messageOpts.projectId }}") #{translate("open_project")} span().notification_close button(ng-click="dismiss(notification)").close.pull-right