escape data on room enter

v1.18.x
barisusakli 10 years ago
parent 7dde229517
commit c8e0eab34e

@ -70,6 +70,10 @@ SocketMeta.rooms.enter = function(socket, data, callback) {
socket.currentRoom = data.enter; socket.currentRoom = data.enter;
if (data.enter.indexOf('topic') !== -1) { if (data.enter.indexOf('topic') !== -1) {
data.uid = socket.uid; data.uid = socket.uid;
data.picture = validator.escape(data.picture);
data.username = validator.escape(data.username);
data.userslug = validator.escape(data.userslug);
websockets.in(data.enter).emit('event:user_enter', data); websockets.in(data.enter).emit('event:user_enter', data);
} }
} }

Loading…
Cancel
Save