- Provider-controlled strings (channel names, groups, file names, log lines, in-place mapping edits, client info) are rendered with textContent instead of innerHTML. PopupContent.description() takes an explicit isHTML flag that only the static help texts pass. - Websocket: drop the always-true CheckOrigin so gorilla's same-origin check applies; read the session token from the HttpOnly cookie sent with the handshake (the ?Token= query parameter is still accepted for older clients); the client no longer puts the token in the URL, rewrites the cookie, or console-logs request/response payloads. - Session cookie is HttpOnly, SameSite=Strict, Path=/, session-scoped (expiry stays server side) and is cleared on logout. - Serving the first-run wizard no longer sets Settings.AuthenticationWEB to false; the wizard page simply bypasses login while it is active. - Upgrade failures no longer write a second error response. - Tests: src/websocket_test.go covers cross-origin refusal, same-origin and no-Origin clients, missing/unknown/legacy tokens, and cookie flags.
This commit is contained in:
+21
-16
@@ -12,7 +12,7 @@ class MainMenu {
|
||||
|
||||
createValue(value):any {
|
||||
var element = document.createElement("P")
|
||||
element.innerHTML = value
|
||||
element.textContent = value
|
||||
return element
|
||||
}
|
||||
}
|
||||
@@ -85,7 +85,7 @@ class Content {
|
||||
|
||||
createHeadline(value):any {
|
||||
var element = document.createElement("H3")
|
||||
element.innerHTML = value
|
||||
element.textContent = value
|
||||
return element
|
||||
}
|
||||
|
||||
@@ -531,7 +531,7 @@ class Cell {
|
||||
switch(this.childType){
|
||||
case "P":
|
||||
element = document.createElement(this.childType);
|
||||
element.innerHTML = this.value
|
||||
element.textContent = this.value
|
||||
element.className = this.className
|
||||
break
|
||||
|
||||
@@ -586,7 +586,7 @@ class Cell {
|
||||
td.appendChild(element)
|
||||
|
||||
} else {
|
||||
td.innerHTML = this.value
|
||||
td.textContent = this.value
|
||||
}
|
||||
|
||||
if (this.onclick == true) {
|
||||
@@ -1081,7 +1081,7 @@ function setClientInfoValue(key:string, value:any) {
|
||||
return
|
||||
}
|
||||
|
||||
element.innerHTML = textValue
|
||||
element.textContent = textValue
|
||||
}
|
||||
|
||||
function createLayout() {
|
||||
@@ -1266,12 +1266,17 @@ class PopupContent extends PopupWindow{
|
||||
return select
|
||||
}
|
||||
|
||||
description(value:string):any {
|
||||
// isHTML must only be true for static text written in the source; never for data.
|
||||
description(value:string, isHTML:boolean = false):any {
|
||||
var tr = document.createElement("TR")
|
||||
var td = document.createElement("TD")
|
||||
var span = document.createElement("PRE")
|
||||
|
||||
span.innerHTML = value
|
||||
if (isHTML) {
|
||||
span.innerHTML = value
|
||||
} else {
|
||||
span.textContent = value
|
||||
}
|
||||
|
||||
tr.appendChild(td)
|
||||
|
||||
@@ -1398,7 +1403,7 @@ function openPopUp(dataType, element) {
|
||||
content.appendRow("Tuner / Streams", input)
|
||||
}
|
||||
|
||||
content.description("Number of parallel connections that can be established to the provider. <br>Only available with activated buffer.<br>New settings will only be applied after quitting all streams.")
|
||||
content.description("Number of parallel connections that can be established to the provider. <br>Only available with activated buffer.<br>New settings will only be applied after quitting all streams.", true)
|
||||
|
||||
// Interaktion
|
||||
content.createInteraction()
|
||||
@@ -1477,7 +1482,7 @@ function openPopUp(dataType, element) {
|
||||
content.appendRow("Tuner / Streams", input)
|
||||
}
|
||||
|
||||
content.description("Number of parallel connections that can be established to the provider. <br>Only available with activated buffer.<br>New settings will only be applied after quitting all streams.")
|
||||
content.description("Number of parallel connections that can be established to the provider. <br>Only available with activated buffer.<br>New settings will only be applied after quitting all streams.", true)
|
||||
|
||||
// Interaktion
|
||||
content.createInteraction()
|
||||
@@ -1597,7 +1602,7 @@ function openPopUp(dataType, element) {
|
||||
var select = content.createSelect(text, values, data[dbKey], dbKey)
|
||||
select.setAttribute("onchange", "javascript: this.className = 'changed'")
|
||||
content.appendRow("Group Title", select)
|
||||
content.description("Select a M3U group. (Counter)<br>Changing the group title in the M3U invalidates the filter.")
|
||||
content.description("Select a M3U group. (Counter)<br>Changing the group title in the M3U invalidates the filter.", true)
|
||||
|
||||
// Groß- Kleinschreibung beachten
|
||||
var dbKey:string = "caseSensitive"
|
||||
@@ -1611,13 +1616,13 @@ function openPopUp(dataType, element) {
|
||||
input.setAttribute("placeholder", "FHD,UHD")
|
||||
|
||||
content.appendRow("Include", input)
|
||||
content.description("Channel name must include.<br>(Comma separated) Comma means or")
|
||||
content.description("Channel name must include.<br>(Comma separated) Comma means or", true)
|
||||
|
||||
var dbKey:string = "exclude"
|
||||
var input = content.createInput("text", dbKey, data[dbKey])
|
||||
input.setAttribute("placeholder", "ES,IT")
|
||||
content.appendRow("Exclude", input)
|
||||
content.description("Channel name must not contain.<br>(Comma separated) Comma means or")
|
||||
content.description("Channel name must not contain.<br>(Comma separated) Comma means or", true)
|
||||
|
||||
break
|
||||
|
||||
@@ -2359,7 +2364,7 @@ function donePopupData(dataType:string, idsStr:string) {
|
||||
break
|
||||
|
||||
case "x-name":
|
||||
(document.getElementById(id).childNodes[3].firstChild as HTMLElement).innerHTML = value
|
||||
(document.getElementById(id).childNodes[3].firstChild as HTMLElement).textContent = value
|
||||
break
|
||||
|
||||
case "x-category":
|
||||
@@ -2367,7 +2372,7 @@ function donePopupData(dataType:string, idsStr:string) {
|
||||
break
|
||||
|
||||
case "x-group-title":
|
||||
(document.getElementById(id).childNodes[5].firstChild as HTMLElement).innerHTML = value
|
||||
(document.getElementById(id).childNodes[5].firstChild as HTMLElement).textContent = value
|
||||
break
|
||||
|
||||
case "x-xmltv-file":
|
||||
@@ -2379,7 +2384,7 @@ function donePopupData(dataType:string, idsStr:string) {
|
||||
input["x-active"] = false
|
||||
}
|
||||
|
||||
(document.getElementById(id).childNodes[6].firstChild as HTMLElement).innerHTML = value
|
||||
(document.getElementById(id).childNodes[6].firstChild as HTMLElement).textContent = value
|
||||
break
|
||||
|
||||
case "x-mapping":
|
||||
@@ -2387,7 +2392,7 @@ function donePopupData(dataType:string, idsStr:string) {
|
||||
input["x-active"] = false
|
||||
}
|
||||
|
||||
(document.getElementById(id).childNodes[7].firstChild as HTMLElement).innerHTML = value
|
||||
(document.getElementById(id).childNodes[7].firstChild as HTMLElement).textContent = value
|
||||
|
||||
break
|
||||
|
||||
|
||||
Reference in New Issue
Block a user