瀏覽代碼

Merge remote-tracking branch 'origin/2.0' into 2.0

jqh 4 年之前
父節點
當前提交
c16440eae8
共有 1 個文件被更改,包括 3 次插入1 次删除
  1. 3 1
      src/Http/Controllers/PermissionController.php

+ 3 - 1
src/Http/Controllers/PermissionController.php

@@ -33,7 +33,9 @@ class PermissionController extends AdminController
             $tree->disableEditButton();
 
             $tree->branch(function ($branch) {
-                $payload = "<div class='pull-left' style='min-width:310px'><b>{$branch['name']}</b>&nbsp;&nbsp;[<span class='text-primary'>{$branch['slug']}</span>]";
+                $branchName = htmlspecialchars($branch['name']);
+                $branchSlug = htmlspecialchars($branch['slug']);
+                $payload = "<div class='pull-left' style='min-width:310px'><b>{$branchName}</b>&nbsp;&nbsp;[<span class='text-primary'>{$branchSlug}</span>]";
 
                 $path = array_filter($branch['http_path']);