From 304033445a8333cd088910fc3e43ca9222237816 Mon Sep 17 00:00:00 2001 From: robertlo Date: Mon, 8 Jan 2018 17:08:00 -0500 Subject: Harden code Issue-ID: PORTAL-145 Harden code to address Open Redirect in Portal SDK Change-Id: If7e923366be11b78c1359dfe5b8fc14a2927c668 Signed-off-by: robertlo --- .../app/fusion/scripts/DS2-view-models/ds2-admin/collaboration.html | 6 ------ .../directives/dashboard/WidgetSettingsRaptorReportCtrl.js | 5 +++-- 2 files changed, 3 insertions(+), 8 deletions(-) (limited to 'ecomp-sdk/epsdk-app-overlay/src/main/webapp/app/fusion/scripts') diff --git a/ecomp-sdk/epsdk-app-overlay/src/main/webapp/app/fusion/scripts/DS2-view-models/ds2-admin/collaboration.html b/ecomp-sdk/epsdk-app-overlay/src/main/webapp/app/fusion/scripts/DS2-view-models/ds2-admin/collaboration.html index cca54a6b..f2bd0bc9 100644 --- a/ecomp-sdk/epsdk-app-overlay/src/main/webapp/app/fusion/scripts/DS2-view-models/ds2-admin/collaboration.html +++ b/ecomp-sdk/epsdk-app-overlay/src/main/webapp/app/fusion/scripts/DS2-view-models/ds2-admin/collaboration.html @@ -149,12 +149,6 @@
- diff --git a/ecomp-sdk/epsdk-app-overlay/src/main/webapp/app/fusion/scripts/view-models/reportdashboard-page/src/components/directives/dashboard/WidgetSettingsRaptorReportCtrl.js b/ecomp-sdk/epsdk-app-overlay/src/main/webapp/app/fusion/scripts/view-models/reportdashboard-page/src/components/directives/dashboard/WidgetSettingsRaptorReportCtrl.js index fd6a0b02..4aabe3ad 100644 --- a/ecomp-sdk/epsdk-app-overlay/src/main/webapp/app/fusion/scripts/view-models/reportdashboard-page/src/components/directives/dashboard/WidgetSettingsRaptorReportCtrl.js +++ b/ecomp-sdk/epsdk-app-overlay/src/main/webapp/app/fusion/scripts/view-models/reportdashboard-page/src/components/directives/dashboard/WidgetSettingsRaptorReportCtrl.js @@ -173,8 +173,9 @@ angular.module('ui.dashboard') function(response) { console.log(response.data); $scope.showChart = true; - document.getElementById('chartiframe').contentWindow.document.write(response.data); - document.getElementById('chartiframe').contentWindow.document.close(); + var chartiframe = document.getElementById('chartiframe'); + chartiframe.contentWindow.document.write(response.data); + chartiframe.contentWindow.document.close(); }); } else { $scope.showChart = false; -- cgit 1.2.3-korg