From 135eb0dfcb4a8ef4c9e31693ea0b94ca43cff4a7 Mon Sep 17 00:00:00 2001 From: Andrew Jarrell <44619184+A-Jarrell@users.noreply.github.com> Date: Mon, 21 Jan 2019 10:12:25 -0800 Subject: [PATCH 1/2] Sanitize faceted search item's title https://github.com/bigcommerce/cornerstone/issues/1416 --- templates/components/faceted-search/facets/multi.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/templates/components/faceted-search/facets/multi.html b/templates/components/faceted-search/facets/multi.html index 23da87eaeb..bad2f23d65 100644 --- a/templates/components/faceted-search/facets/multi.html +++ b/templates/components/faceted-search/facets/multi.html @@ -30,7 +30,7 @@
class="navList-action navList-action--checkbox {{#if selected }} is-selected {{/if}}" rel="nofollow" data-faceted-search-facet> - {{ title }} + {{ sanitize title }} {{#if ../show_product_counts}} ({{ count }}) {{/if}} From 14980bb0a7d8c9a873cc84160f2dbe25fcbf83ff Mon Sep 17 00:00:00 2001 From: Andrew Jarrell <44619184+A-Jarrell@users.noreply.github.com> Date: Tue, 5 Feb 2019 10:52:50 -0800 Subject: [PATCH 2/2] Update CHANGELOG.md --- CHANGELOG.md | 1 + 1 file changed, 1 insertion(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 60226d667b..08cc980bfa 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -11,6 +11,7 @@ - Fix cart item quantity change rollback [#1418](https://github.com/bigcommerce/cornerstone/pull/1418) - Changed z-index to higher for header [#1422](https://github.com/bigcommerce/cornerstone/pull/1422) - Removed customer (not address) phone number requirement from Edit Account [#1417](https://github.com/bigcommerce/cornerstone/pull/1417) +- Sanitize faceted search titles to remove HTML [#1426](https://github.com/bigcommerce/cornerstone/pull/1426) ## 3.0.0 (2018-12-21) ### Breaking Changes