浏览代码

Hotfix login (#4680)

* FIx XSS Sanitize

* Don't sanitize password
version-14
Faris Ansari 7 年前
committed by Nabin Hait
父节点
当前提交
6d03ebd1c6
共有 1 个文件被更改,包括 1 次插入1 次删除
  1. +1
    -1
      frappe/templates/includes/login/login.js

+ 1
- 1
frappe/templates/includes/login/login.js 查看文件

@@ -18,7 +18,7 @@ login.bind_events = function() {
var args = {}; var args = {};
args.cmd = "login"; args.cmd = "login";
args.usr = frappe.utils.xss_sanitise(($("#login_email").val() || "").trim()); args.usr = frappe.utils.xss_sanitise(($("#login_email").val() || "").trim());
args.pwd = frappe.utils.xss_sanitise($("#login_password").val());
args.pwd = $("#login_password").val();
args.device = "desktop"; args.device = "desktop";
if(!args.usr || !args.pwd) { if(!args.usr || !args.pwd) {
frappe.msgprint("{{ _("Both login and password required") }}"); frappe.msgprint("{{ _("Both login and password required") }}");


正在加载...
取消
保存