mirror of
https://github.com/nextcloud/server.git
synced 2026-04-21 14:23:17 -04:00
Make the translation sanitization optional
Signed-off-by: Christoph Wurst <christoph@winzerhof-wurst.at>
This commit is contained in:
parent
a0771a389a
commit
74db91910c
17 changed files with 141 additions and 139 deletions
6
core/js/dist/files_client.js
vendored
6
core/js/dist/files_client.js
vendored
File diff suppressed because one or more lines are too long
2
core/js/dist/files_client.js.map
vendored
2
core/js/dist/files_client.js.map
vendored
File diff suppressed because one or more lines are too long
2
core/js/dist/files_fileinfo.js
vendored
2
core/js/dist/files_fileinfo.js
vendored
File diff suppressed because one or more lines are too long
2
core/js/dist/files_fileinfo.js.map
vendored
2
core/js/dist/files_fileinfo.js.map
vendored
File diff suppressed because one or more lines are too long
2
core/js/dist/files_iedavclient.js
vendored
2
core/js/dist/files_iedavclient.js
vendored
File diff suppressed because one or more lines are too long
2
core/js/dist/files_iedavclient.js.map
vendored
2
core/js/dist/files_iedavclient.js.map
vendored
File diff suppressed because one or more lines are too long
32
core/js/dist/install.js
vendored
32
core/js/dist/install.js
vendored
File diff suppressed because one or more lines are too long
2
core/js/dist/install.js.map
vendored
2
core/js/dist/install.js.map
vendored
File diff suppressed because one or more lines are too long
44
core/js/dist/login.js
vendored
44
core/js/dist/login.js
vendored
File diff suppressed because one or more lines are too long
2
core/js/dist/login.js.map
vendored
2
core/js/dist/login.js.map
vendored
File diff suppressed because one or more lines are too long
116
core/js/dist/main.js
vendored
116
core/js/dist/main.js
vendored
File diff suppressed because one or more lines are too long
2
core/js/dist/main.js.map
vendored
2
core/js/dist/main.js.map
vendored
File diff suppressed because one or more lines are too long
40
core/js/dist/maintenance.js
vendored
40
core/js/dist/maintenance.js
vendored
File diff suppressed because one or more lines are too long
2
core/js/dist/maintenance.js.map
vendored
2
core/js/dist/maintenance.js.map
vendored
File diff suppressed because one or more lines are too long
4
core/js/dist/recommendedapps.js
vendored
4
core/js/dist/recommendedapps.js
vendored
File diff suppressed because one or more lines are too long
2
core/js/dist/recommendedapps.js.map
vendored
2
core/js/dist/recommendedapps.js.map
vendored
File diff suppressed because one or more lines are too long
|
|
@ -12,6 +12,7 @@ import _ from 'underscore'
|
|||
import $ from 'jquery'
|
||||
import DOMPurify from 'dompurify'
|
||||
import Handlebars from 'handlebars'
|
||||
import identity from 'lodash/fp/identity'
|
||||
import escapeHTML from 'escape-html'
|
||||
|
||||
import OC from './index'
|
||||
|
|
@ -84,15 +85,20 @@ const L10n = {
|
|||
* @param {number} [count] number to replace %n with
|
||||
* @param {array} [options] options array
|
||||
* @param {bool} [options.escape=true] enable/disable auto escape of placeholders (by default enabled)
|
||||
* @param {bool} [options.sanitize=true] enable/disable sanitization (by default enabled)
|
||||
* @returns {string}
|
||||
*/
|
||||
translate: function(app, text, vars, count, options) {
|
||||
const defaultOptions = {
|
||||
escape: true,
|
||||
sanitize: true,
|
||||
}
|
||||
const allOptions = options || {}
|
||||
_.defaults(allOptions, defaultOptions)
|
||||
|
||||
const optSanitize = allOptions.sanitize ? DOMPurify.sanitize : identity
|
||||
const optEscape = allOptions.escape ? escapeHTML : identity
|
||||
|
||||
// TODO: cache this function to avoid inline recreation
|
||||
// of the same function over and over again in case
|
||||
// translate() is used in a loop
|
||||
|
|
@ -101,13 +107,9 @@ const L10n = {
|
|||
function(a, b) {
|
||||
const r = vars[b]
|
||||
if (typeof r === 'string' || typeof r === 'number') {
|
||||
if (allOptions.escape) {
|
||||
return DOMPurify.sanitize(escapeHTML(r))
|
||||
} else {
|
||||
return DOMPurify.sanitize(r)
|
||||
}
|
||||
return optSanitize(optEscape(r))
|
||||
} else {
|
||||
return DOMPurify.sanitize(a)
|
||||
return optSanitize(a)
|
||||
}
|
||||
}
|
||||
)
|
||||
|
|
@ -120,9 +122,9 @@ const L10n = {
|
|||
}
|
||||
|
||||
if (typeof vars === 'object' || count !== undefined) {
|
||||
return DOMPurify.sanitize(_build(translation, vars, count))
|
||||
return optSanitize(_build(translation, vars, count))
|
||||
} else {
|
||||
return DOMPurify.sanitize(translation)
|
||||
return optSanitize(translation)
|
||||
}
|
||||
},
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue