| @@ -42,11 +42,22 @@ | ||
| 42 | 42 | if (options.hasOwnProperty("duration")) { |
| 43 | 43 | this.duration = options.duration; |
| 44 | 44 | } |
| 45 | 45 | /*create toast*/ |
| 46 | + /* The message is rendered as text only. No markup is built from it, so there is | |
| 47 | + nothing for an attacker to break out of. */ | |
| 46 | 48 | let toastDiv = document.createElement("div"); |
| 47 | - let elemHTML = '<span class="__tagembed__faicon"><i class="fas ' + this.icon + '" aria-hidden="true"></i></span><span class="__tagembed__btnmsg">' + this.message + '</span>'; | |
| 48 | - toastDiv.innerHTML = elemHTML; | |
| 49 | + let toastIconSpan = document.createElement("span"); | |
| 50 | + toastIconSpan.className = "__tagembed__faicon"; | |
| 51 | + let toastIcon = document.createElement("i"); | |
| 52 | + toastIcon.className = "fas " + this.icon; | |
| 53 | + toastIcon.setAttribute("aria-hidden", "true"); | |
| 54 | + toastIconSpan.appendChild(toastIcon); | |
| 55 | + let toastMessageSpan = document.createElement("span"); | |
| 56 | + toastMessageSpan.className = "__tagembed__btnmsg"; | |
| 57 | + toastMessageSpan.textContent = (this.message === undefined || this.message === null) ? "" : String(this.message); | |
| 58 | + toastDiv.appendChild(toastIconSpan); | |
| 59 | + toastDiv.appendChild(toastMessageSpan); | |
| 49 | 60 | toastDiv.className = this.type; |
| 50 | 61 | let toastParentDiv = document.createElement("div"); |
| 51 | 62 | toastParentDiv.setAttribute('id', this.id); |
| 52 | 63 | toastParentDiv.className = this.className + " " + this.position; |