mirror of
https://github.com/discourse/discourse.git
synced 2025-05-22 22:43:33 +08:00
SECURITY: Cross-Site Scripting in Category and Group Settings
This commit is contained in:
@ -109,7 +109,13 @@ export default function() {
|
||||
});
|
||||
|
||||
this.put('/categories/:category_id', request => {
|
||||
|
||||
const category = parsePostData(request.requestBody);
|
||||
|
||||
if (category.email_in === "duplicate@example.com") {
|
||||
return response(422, {"errors": ['duplicate email']});
|
||||
}
|
||||
|
||||
return response({category});
|
||||
});
|
||||
|
||||
|
Reference in New Issue
Block a user