Compare commits

...

6 Commits

Author SHA1 Message Date
fit2bot
cb9f843d42 feat: Update v3.5.5 2023-09-11 16:54:30 +08:00
Bai
2360da53dd fix: 修复账号列表添加账号时会明文显示的问题 2023-08-16 08:14:00 +05:00
老广
17fd374e0a Merge pull request #3322 from jumpserver/pr@v3.5@fix_msg_subscribe_for_xss
fix: 修复系统设置 > 消息订阅 > 修改订阅人 因为用户名导致的 xss
2023-08-08 16:17:09 +08:00
ibuler
df5d15c1e5 fix: 修复系统设置 > 消息订阅 > 修改订阅人 因为用户名导致的 xss 2023-08-08 03:08:02 +00:00
“huailei000”
b58c21a79f perf: 命令记录列表增加账号字段 2023-08-03 16:16:38 +08:00
“huailei000”
3d81f92667 perf: 修改github配置 2023-07-21 14:56:38 +08:00
6 changed files with 1638 additions and 1633 deletions

View File

@@ -42,7 +42,7 @@ jobs:
steps:
- uses: actions/checkout@v2
- name: Build it and upload
uses: jumpserver/action-build-upload-assets@node10
uses: jumpserver/action-build-upload-assets@node14.16
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with:

1
GITSHA Normal file
View File

@@ -0,0 +1 @@
2360da53dd0386ea7f8ec4e26f649aa3451bd8f0

View File

@@ -304,6 +304,9 @@ export default {
form.secret = form[secretType]
form.secret = this.encryptPassword ? encryptPassword(form.secret) : form.secret
// 如果不删除会明文显示
delete form[secretType]
if (!form.secret) {
delete form['secret']
}

View File

@@ -49,7 +49,7 @@ export default {
},
columns: [
'expandCol', 'input', 'risk_level', 'user', 'remote_addr',
'asset', 'session', 'timestamp'
'asset', 'account', 'session', 'timestamp'
],
extraQuery: {
date_to: dateTo,

View File

@@ -2,13 +2,13 @@
<Dialog
ref="myDialog"
:destroy-on-close="true"
width="790px"
height="720px"
v-bind="$attrs"
width="790px"
@confirm="submit"
v-on="$listeners"
>
<krryPaging ref="pageTransfer" v-bind="pagingTransfer" class="transfer" />
<krryPaging ref="pageTransfer" class="transfer" v-bind="pagingTransfer" />
</Dialog>
</template>
@@ -16,6 +16,7 @@
import Dialog from '@/components/Dialog'
import { krryPaging } from 'krry-transfer'
import { getUserList } from '@/api/users'
export default {
name: 'ListSelect',
components: {
@@ -47,7 +48,7 @@ export default {
}
const data = await getUserList(params)
const results = data['results'].map(item => {
return { id: item.id, label: `${item.name}(${item.username})` }
return { id: item.id, label: _.escape(`${item.name}(${item.username})`) }
})
return results
},
@@ -62,7 +63,7 @@ export default {
}
const data = await getUserList(params)
const results = data['results'].map(item => {
return { id: item.id, label: `${item.name}(${item.username})` }
return { id: item.id, label: _.escape(`${item.name}(${item.username})`) }
})
return results
},

3254
yarn.lock

File diff suppressed because it is too large Load Diff