| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
1 parent ad3fad3 commit 7e3220e
2 files changed
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -6,6 +6,7 @@ var cookieParser = require('cookie-parser')(); | |||
| 6 | 6 | var moment = require('moment'); | |
| 7 | 7 | var pluralize = require('pluralize'); | |
| 8 | 8 | var expressValidator = require('express-validator'); | |
| 9 | + var marked = require('marked'); | ||
| 9 | 10 | var Articles = require(path.join(__dirname, '..', 'models', 'articles')); | |
| 10 | 11 | var Users = require(path.join(__dirname, '..', 'models', 'users')); | |
| 11 | 12 | var Akismetor = require(path.join(__dirname, '..', 'services', 'akismetor')); | |
@@ -94,15 +95,16 @@ router. | |||
| 94 | 95 | ||
| 95 | 96 | Articles.findBySlug(req.params.slug, function(err, doc) { | |
| 96 | 97 | if(doc){ | |
| 97 | - res.render('news/show', { doc: doc, user: user, token: req.csrfToken(), moment: moment, pluralize: pluralize }); | ||
| 98 | + // doc.body = marked(doc.body); // This sync compiling can become costly | ||
| 99 | + res.render('news/show', { doc: doc, user: user, token: req.csrfToken(), moment: moment, pluralize: pluralize, marked: marked }); | ||
| 98 | 100 | }else{ | |
| 99 | 101 | res.render('404'); | |
| 100 | 102 | } | |
| 101 | 103 | }); | |
| 102 | 104 | }). | |
| 103 | 105 | ||
| 104 | 106 | post('/:slug([a-zA-Z0-9_.-]+)/comment', cookieParser, authenticator.authorize, parseForm, expressValidator(), csrfProtection, buildComment, function(req, res) { | |
| 105 | - req.sanitize('body').trim(); | ||
| 107 | + req.sanitize('body').escape().trim(); | ||
| 106 | 108 | req.check('body').notEmpty(); | |
| 107 | 109 | ||
| 108 | 110 | var errors = req.validationErrors(); | |
@@ -118,7 +120,10 @@ router. | |||
| 118 | 120 | } | |
| 119 | 121 | }). | |
| 120 | 122 | ||
| 121 | - put('/:slug([a-zA-Z0-9_.-]+)/comment/:id([a-zA-Z0-9_.-]+)', cookieParser, authenticator.authorize, parseForm, csrfProtection, function(req, res) { | ||
| 123 | + put('/:slug([a-zA-Z0-9_.-]+)/comment/:id([a-zA-Z0-9_.-]+)', cookieParser, authenticator.authorize, parseForm, expressValidator(), csrfProtection, function(req, res) { | ||
| 124 | + req.sanitize('body').escape().trim(); | ||
| 125 | + req.check('body').notEmpty(); | ||
| 126 | + | ||
| 122 | 127 | var args = { | |
| 123 | 128 | updatedComment : req.body.body, | |
| 124 | 129 | commentId : req.params.id, | |
@@ -151,6 +156,9 @@ router. | |||
| 151 | 156 | ||
| 152 | 157 | post('/', cookieParser, authenticator.authorize, parseForm, addhttp, expressValidator(), csrfProtection, function(req, res) { | |
| 153 | 158 | ||
| 159 | + req.sanitize('body').escape().trim(); | ||
| 160 | + req.check('body').notEmpty(); | ||
| 161 | + | ||
| 154 | 162 | // Validations | |
| 155 | 163 | req.check('title','Title is required' ).notEmpty(); | |
| 156 | 164 | req.check('url', 'URL is required').notEmpty(); | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -33,7 +33,7 @@ block content | |||
| 33 | 33 | li.list-item | |
| 34 | 34 | a.dib.js-createComment-number.js-editComment-number(href='#comments')= pluralize('Comment', doc.comment_count, true) | |
| 35 | 35 | ||
| 36 | - p.well.well--l.tsl= doc.body | ||
| 36 | + p.well.well--l.tsl!= marked(doc.body) | ||
| 37 | 37 | ||
| 38 | 38 | - commentsClass = doc.comment_count == 0 ? 'is-empty' : '' | |
| 39 | 39 | aside#comments.js-createComment-container(role='complementary' class=commentsClass) | |
@@ -59,7 +59,8 @@ block content | |||
| 59 | 59 | .split-cell | |
| 60 | 60 | button.link.js-editComment-editBtn Edit | |
| 61 | 61 | ||
| 62 | - p.mbf.js-editComment-comment= comment.body | ||
| 62 | + .mbf.js-editComment-comment | ||
| 63 | + != marked(comment.body) | ||
| 63 | 64 | ||
| 64 | 65 | if comment.user.id == user.id | |
| 65 | 66 | ||
| Back | FazBrowse Home | New Git URL |
0 commit comments