Skip to content

Commit

Permalink
WEBUI-1510: Own Code Static Scan : Cross-Site Scripting (XSS)
Browse files Browse the repository at this point in the history
  • Loading branch information
rahuljain-dev committed May 17, 2024
1 parent a0ad30c commit 657f5bc
Showing 1 changed file with 19 additions and 13 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -20,8 +20,6 @@ import { config } from '@nuxeo/nuxeo-elements';
import { FormatBehavior } from '@nuxeo/nuxeo-ui-elements/nuxeo-format-behavior.js';
import { RoutingBehavior } from '@nuxeo/nuxeo-ui-elements/nuxeo-routing-behavior.js';

let schemaFetcher = null;

/**
* `Nuxeo.DocumentCreationBehavior`
*
Expand Down Expand Up @@ -78,26 +76,34 @@ export const DocumentCreationBehavior = [
subtypes: {
type: Array,
},

_resource: {
type: Object,
readOnly: true,
},
},

get resource() {
if (!this._resource) {
this._set_resource(document.createElement('nuxeo-resource'));
this.shadowRoot.appendChild(this._resource);
}
return this._resource;
},

observers: ['_validateLocation(isValidTargetPath,suggesterChildren)', '_updateDocument(selectedDocType, parent)'],

newDocument(type, properties) {
if (!schemaFetcher) {
schemaFetcher = document.createElement('div');
schemaFetcher.innerHTML = '<nuxeo-resource></nuxeo-resource>';
this.shadowRoot.appendChild(schemaFetcher);
[schemaFetcher] = schemaFetcher.getElementsByTagName('nuxeo-resource');
}
schemaFetcher.path = `path/${this.targetPath}/@emptyWithDefault`;
schemaFetcher.params = { type: this.selectedDocType.type };
schemaFetcher.headers = {
const { resource } = this;
resource.path = `path/${this.targetPath}/@emptyWithDefault`;
resource.params = { type: this.selectedDocType.type };
resource.headers = {
properties: '*',
'fetch-document': 'properties',
'translate-directoryEntry': 'label',
};
schemaFetcher.enrichers = config.get('enrichers', {});
return schemaFetcher.get().then((doc) => {
resource.enrichers = config.get('enrichers', {});
return resource.get().then((doc) => {
if (properties) {
Object.keys(properties).forEach((prop) => {
doc.properties[prop] = properties[prop];
Expand Down

0 comments on commit 657f5bc

Please sign in to comment.