escape error message on 500 page

v1.18.x
Barış Soner Uşaklı 9 years ago
parent 7b21760f00
commit cdca09a7b2

@ -6,6 +6,7 @@ var nconf = require('nconf'),
controllers = require('../controllers'), controllers = require('../controllers'),
plugins = require('../plugins'), plugins = require('../plugins'),
express = require('express'), express = require('express'),
validator = require('validator'),
accountRoutes = require('./accounts'), accountRoutes = require('./accounts'),
@ -195,7 +196,7 @@ function handleErrors(app, middleware) {
res.json({path: req.path, error: err.message}); res.json({path: req.path, error: err.message});
} else { } else {
middleware.buildHeader(req, res, function() { middleware.buildHeader(req, res, function() {
res.render('500', {path: req.path, error: err.message}); res.render('500', {path: req.path, error: validator.escape(err.message)});
}); });
} }
}); });

Loading…
Cancel
Save