Fix reflected XSS in 'key' parameter. Fixes #461
This commit is contained in:
@@ -40,7 +40,7 @@ module.exports.getTileUrls = (req, domains, path, format, publicUrl, aliases) =>
|
||||
const key = req.query.key;
|
||||
const queryParams = [];
|
||||
if (req.query.key) {
|
||||
queryParams.push(`key=${req.query.key}`);
|
||||
queryParams.push(`key=${encodeURIComponent(req.query.key)}`);
|
||||
}
|
||||
if (req.query.style) {
|
||||
queryParams.push(`style=${req.query.style}`);
|
||||
|
||||
Reference in New Issue
Block a user