From 46031cd4059b5c6dc52ef8064f8f0754f2360d6e Mon Sep 17 00:00:00 2001 From: chiu Date: Sun, 26 Apr 2020 12:38:07 +0800 Subject: [PATCH] add xss protection --- app/controllers/personal_conferences_controller.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/controllers/personal_conferences_controller.rb b/app/controllers/personal_conferences_controller.rb index 6e00c08..91ddc54 100644 --- a/app/controllers/personal_conferences_controller.rb +++ b/app/controllers/personal_conferences_controller.rb @@ -118,7 +118,7 @@ class PersonalConferencesController < ApplicationController 'url' => '/' + params[:locale] + params[:url], 'select_text' => select_text, 'search_text' => search_text, - 'search_value' => params[:keywords], + 'search_value' => params[:keywords].gsub(/\"/,''), 'csrf_value' => csrf_value }, 'headers' => headers, 'total_pages' => writing_conferences_total_pages,