mirror of
				https://github.com/NodeBB/NodeBB.git
				synced 2025-10-31 19:15:58 +01:00 
			
		
		
		
	fix: escape system message, don't allow editing system messages
This commit is contained in:
		| @@ -1,5 +1,7 @@ | ||||
| 'use strict'; | ||||
|  | ||||
| const validator = require('validator'); | ||||
|  | ||||
| var db = require('../database'); | ||||
| var user = require('../user'); | ||||
| var utils = require('../utils'); | ||||
| @@ -79,6 +81,7 @@ module.exports = function (Messaging) { | ||||
|  | ||||
| 		messages = await Promise.all(messages.map(async (message) => { | ||||
| 			if (message.system) { | ||||
| 				message.content = validator.escape(String(message.content)); | ||||
| 				return message; | ||||
| 			} | ||||
|  | ||||
|   | ||||
		Reference in New Issue
	
	Block a user