use safer indirect eval
This commit is contained in:
parent
027670c21c
commit
8ff81537f2
@ -214,7 +214,7 @@ export const applyEvent = async (event, socket) => {
|
|||||||
a.href = event.payload.url;
|
a.href = event.payload.url;
|
||||||
// Special case when linking to uploaded files
|
// Special case when linking to uploaded files
|
||||||
if (a.href.includes("getBackendURL(env.UPLOAD)")) {
|
if (a.href.includes("getBackendURL(env.UPLOAD)")) {
|
||||||
a.href = eval(
|
a.href = eval?.(
|
||||||
event.payload.url.replace(
|
event.payload.url.replace(
|
||||||
"getBackendURL(env.UPLOAD)",
|
"getBackendURL(env.UPLOAD)",
|
||||||
`"${getBackendURL(env.UPLOAD)}"`
|
`"${getBackendURL(env.UPLOAD)}"`
|
||||||
|
Loading…
Reference in New Issue
Block a user