Skip to content

Commit

Permalink
Merge pull request #93 from chihiro-adachi/fix-payment
Browse files Browse the repository at this point in the history
支払方法設定のXSS対応
  • Loading branch information
okazy authored Jun 22, 2021
2 parents c0cbef4 + 761d3b9 commit 71704b5
Showing 1 changed file with 4 additions and 2 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -69,7 +69,8 @@ Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
if ($("#{{ form.payment_image.vars.id }}").val() != "") {
var filename = $("#{{ form.payment_image.vars.id }}").val();
var path = '{{ app.config.image_save_urlpath }}/' + filename;
var $img = $(proto_img.replace(/__path__/g, path));
var $img = $(proto_img);
$('img', $img).attr('src', path);
$("#{{ form.payment_image.vars.id }}").val(filename);
$('#thumb').append($img);
Expand All @@ -83,7 +84,8 @@ Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
done: function (e, data) {
$('#progress').hide();
var path = '{{ app.config.image_temp_urlpath }}/' + data.result.filename;
var $img = $(proto_img.replace(/__path__/g, path));
var $img = $(proto_img);
$('img', $img).attr('src', path);
$("#{{ form.payment_image.vars.id }}").val(data.result.filename);
$('#thumb').append($img);
Expand Down

0 comments on commit 71704b5

Please sign in to comment.