mirror of
https://gerrit.wikimedia.org/r/mediawiki/extensions/Echo
synced 2024-09-24 10:49:37 +00:00
Add escaping for paranoia
Change-Id: I53fde56d67d5515deb4e296c14cc84d7a5cb1036
This commit is contained in:
parent
429b608270
commit
3ede5a482a
|
@ -50,7 +50,7 @@ class SpecialNotifications extends SpecialPage {
|
|||
$class .= ' mw-echo-unread';
|
||||
}
|
||||
|
||||
$eventType = $event->getType();
|
||||
$eventType = htmlspecialchars( $event->getType() );
|
||||
$html .= "\t<li class=\"$class\" data-notification-type=\"$eventType\">$formatted</li>\n";
|
||||
}
|
||||
|
||||
|
|
Loading…
Reference in a new issue