From 6c650199b40b62a261607cd73a228b04e9fff7e3 Mon Sep 17 00:00:00 2001 From: chiu Date: Sun, 26 Apr 2020 12:38:45 +0800 Subject: [PATCH] add xss protection --- app/controllers/personal_projects_controller.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/controllers/personal_projects_controller.rb b/app/controllers/personal_projects_controller.rb index 589e39a..eeabb18 100644 --- a/app/controllers/personal_projects_controller.rb +++ b/app/controllers/personal_projects_controller.rb @@ -96,7 +96,7 @@ class PersonalProjectsController < ApplicationController 'url' => '/' + params[:locale] + params[:url], 'select_text' => select_text, 'search_text' => search_text, - 'search_value' => params[:keywords], + 'search_value' => params[:keywords].gsub(/\"/,''), 'csrf_value' => csrf_value }, 'total_pages' => projects_total_pages, 'choice' => choice