HTML-escape label values in Rickshaw hover-detail.

pull/610/head
Julius Volz 10 years ago
parent 942686427d
commit 8f6ef04d70

@ -365,7 +365,7 @@ Prometheus.Graph.prototype.renderLabels = function(labels) {
var labelStrings = [];
for (label in labels) {
if (label != "__name__") {
labelStrings.push("<strong>" + label + "</strong>: " + labels[label]);
labelStrings.push("<strong>" + label + "</strong>: " + escapeHTML(labels[label]));
}
}
return labels = "<div class=\"labels\">" + labelStrings.join("<br>") + "</div>";

Loading…
Cancel
Save