Skip to content

Commit

Permalink
Improved: Prevent URL parameters manipulation (OFBIZ-13147)
Browse files Browse the repository at this point in the history
Reverts the revert in OFBIZ-13162
Adds a @SuppressWarnings("unused") to MacroFormRenderer::executeMacro
  • Loading branch information
JacquesLeRoux committed Nov 26, 2024
1 parent eee6ccb commit 578cb53
Show file tree
Hide file tree
Showing 2 changed files with 7 additions and 1 deletion.
Original file line number Diff line number Diff line change
Expand Up @@ -157,6 +157,7 @@ private void executeMacro(Appendable writer, String macro) {
* @param locale
* @param macro
*/
@SuppressWarnings("unused")
private void executeMacro(Appendable writer, Locale locale, String macro) {
ftlWriter.processFtlString(writer, locale, macro);
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -268,7 +268,12 @@ public void renderLink(Appendable writer, Map<String, Object> context, MenuLink
targetParameters.append(parameter.getKey());
targetParameters.append("'");
targetParameters.append(",'value':'");
targetParameters.append(parameter.getValue());
UtilCodec.SimpleEncoder simpleEncoder = (UtilCodec.SimpleEncoder) context.get("simpleEncoder");
if (simpleEncoder != null) {
targetParameters.append(simpleEncoder.encode(parameter.getValue()));
} else {
targetParameters.append(parameter.getValue());
}
targetParameters.append("'}");
}
targetParameters.append("]");
Expand Down

0 comments on commit 578cb53

Please sign in to comment.