Commit Graph

14 Commits

Author SHA1 Message Date
Javi Martín
8b73cfc019 Sanitize annotation context before displaying it
There's a case where we would face a Cross-Site Scripting attack. An
attacker could use the browser's developer tools to add (on their
browser) a `<code>` tag with a `<script>` tag inside in the text of the
draft version. After doing so, commenting on that text would result in
the attacker's JavaScript being executed.
2019-10-08 18:46:20 +02:00
Javi Martín
4c35df4812 Use double quotes inside string interpolation 2019-03-25 14:58:54 +01:00
Julian Herrero
2b83be1c7c Use double quotes in app/views/legislation 2019-03-19 12:16:50 +01:00
decabeza
6f4f161076 Adds help gif on legislation processes with texts 2018-07-05 18:10:06 +02:00
decabeza
ee7ca37d18 Removes unused css 2018-03-07 17:18:27 +01:00
Bertocq
553348eaad Convert phase to symbol before comparision for active dates 2017-09-05 16:18:36 +02:00
Martín González
9962202b0d Invert share buttons layout 2017-02-15 19:47:58 +01:00
Amaia Castro
311388969d Changes annotations text for twitter share button 2017-02-14 18:15:01 +01:00
Amaia Castro
2efa72ddd5 Merge branch 'legislation-module-stable' into 107-social-share-for-annotations 2017-02-14 18:14:00 +01:00
Martín González
af52fb5670 Improve social share buttons position for the annotations index and specific annotations 2017-02-14 17:11:02 +01:00
Amaia Castro
58b9135c71 Add context to annotation in index view 2017-02-13 11:18:33 +01:00
Martín González
076c5d2784 Use the full width key dates html where is possible, fix svg margin 2017-01-18 13:05:16 +01:00
Amaia Castro
f43f13e826 Create first comment automatically from the annotation 2017-01-09 17:03:00 +01:00
Amaia Castro
b8f034d896 Legislation annotations/comments page 2017-01-09 09:29:15 +01:00