Fix xss for person roles

This commit is contained in:
Bill Thornton
2025-10-15 14:31:58 -04:00
parent 0682ca3b99
commit 16fd2a01aa

View File

@@ -970,7 +970,7 @@ function populatePeople(context, people) {
html += '</div>';
if (person.Role && person.Role !== lastType) {
html += '<div class="secondary">' + person.Role + '</div>';
html += '<div class="secondary">' + escapeHtml(person.Role) + '</div>';
} else {
html += '<div class="secondary">' + globalize.translate(person.Type) + '</div>';
}