Browse Source

修复 editable 触发 xss

laradocs 3 years ago
parent
commit
61227db72d
1 changed files with 5 additions and 1 deletions
  1. 5 1
      resources/views/grid/displayer/editinline/template.blade.php

+ 5 - 1
resources/views/grid/displayer/editinline/template.blade.php

@@ -162,7 +162,11 @@
             var data = res.data;
             if (res.status === true) {
                 Dcat.success(data.message);
-                $popover.data('display').html(label || '<i class="feather icon-edit-2"></i>');
+                var $display = $popover.data('display');
+                $display.text(label);
+                if (! label) {
+                    $display.html('<i class="feather icon-edit-2"></i>');
+                }
                 $trigger.data('value', val).data('original', val);
                 hide();
                 refresh && Dcat.reload();