mirror of
https://github.com/GSA/notifications-admin.git
synced 2026-09-08 18:03:12 -04:00
service contact blocks contain new lines - and jinja2 normally ignores
newlines (as in it keeps them as new lines) - but we need to turn them
into `<br>` tags so that we can show the formatting that the user has
added. We were previously just doing `{{ block | nl2br | safe }}`. nl2br
turns the new lines into `<br>` tags, and then `safe` tells jinja that
it doesn't need to escape the html.
this causes issues if the user adds `<script>alert(1)</script>` to their
contact block (or some other evil xss hack), where that will get let
through due to the safe flag
To solve this, use `Markup(html='escape')` to sanitise any html, and
then convert new lines to <br>.
bump utils
another xss
61 lines
2.1 KiB
HTML
61 lines
2.1 KiB
HTML
{% extends "withnav_template.html" %}
|
|
{% from "components/api-key.html" import api_key %}
|
|
{% from "components/page-header.html" import page_header %}
|
|
{% from "components/page-footer.html" import page_footer %}
|
|
{% from "components/table.html" import row_group, row, text_field, edit_field, field, boolean_field, list_table with context %}
|
|
|
|
{% block service_page_title %}
|
|
Sender addresses
|
|
{% endblock %}
|
|
|
|
{% block maincolumn_content %}
|
|
|
|
<div class="bottom-gutter">
|
|
{{ page_header(
|
|
'Sender addresses',
|
|
back_link=url_for('main.service_settings', service_id=current_service.id)
|
|
) }}
|
|
</div>
|
|
<div class="user-list">
|
|
<div class="user-list-item">
|
|
<span class="hint">
|
|
Blank
|
|
{% if current_service.default_letter_contact_block %}
|
|
{% if current_user.has_permissions('manage_service') %}
|
|
<a class="user-list-edit-link" href="{{ url_for('.service_make_blank_default_letter_contact', service_id =current_service.id) }}">Make default</a>
|
|
{% endif %}
|
|
{% else %}
|
|
(default)
|
|
{% endif %}
|
|
</span>
|
|
</div>
|
|
{% for item in letter_contact_details %}
|
|
<div class="user-list-item">
|
|
<p>
|
|
{{ item.contact_block | nl2br }}
|
|
</p>
|
|
<p class="hint">
|
|
{%- if item.is_default -%}
|
|
(default)
|
|
{% endif %}
|
|
</p>
|
|
{% if current_user.has_permissions('manage_service') %}
|
|
<a class="user-list-edit-link" href="{{ url_for('.service_edit_letter_contact', service_id =current_service.id, letter_contact_id = item.id) }}">Change</a>
|
|
{% endif %}
|
|
{% if letter_contact_details|length > 1 %}
|
|
{{ api_key(item.id, thing="ID") }}
|
|
{% endif %}
|
|
</div>
|
|
{% endfor %}
|
|
</div>
|
|
{% if current_user.has_permissions('manage_service') %}
|
|
<div class="grid-row">
|
|
<div class="column-whole">
|
|
<div class="js-stick-at-bottom-when-scrolling">
|
|
<a href="{{ url_for('.service_add_letter_contact', service_id=current_service.id) }}" class="button">Add a new address</a>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
{% endif %}
|
|
{% endblock %}
|