From 0d5d8b671dfdd1e226e41c917e1f14b5a53fc927 Mon Sep 17 00:00:00 2001 From: Kyle Spearrin Date: Thu, 13 May 2021 15:22:52 -0400 Subject: [PATCH] use swal titletext to avoid XSS (#884) --- src/services/electronPlatformUtils.service.ts | 2 +- src/services/nativeMessaging.service.ts | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/src/services/electronPlatformUtils.service.ts b/src/services/electronPlatformUtils.service.ts index ae1c31bc7d..a8989e5e58 100644 --- a/src/services/electronPlatformUtils.service.ts +++ b/src/services/electronPlatformUtils.service.ts @@ -18,7 +18,7 @@ export class ElectronPlatformUtilsService extends BaseElectronPlatformUtilsServi Promise { const result = await Swal.fire({ heightAuto: false, - title: title, + titleText: title, input: 'password', text: body, confirmButtonText: this.i18nService.t('ok'), diff --git a/src/services/nativeMessaging.service.ts b/src/services/nativeMessaging.service.ts index 88ed58e8e9..aad4ed9532 100644 --- a/src/services/nativeMessaging.service.ts +++ b/src/services/nativeMessaging.service.ts @@ -53,7 +53,7 @@ export class NativeMessagingService { // Await confirmation that fingerprint is correct const submitted = await Swal.fire({ - title: this.i18nService.t('verifyBrowserTitle'), + titleText: this.i18nService.t('verifyBrowserTitle'), html: `${this.i18nService.t('verifyBrowserDesc')}

${fingerprint}`, showCancelButton: true, cancelButtonText: this.i18nService.t('cancel'),