Skip to content

Commit fe299ad

Browse files
committed
Merge pull request #24 from pkallos/master
escape HTML in username
2 parents b8ef60a + b5f360f commit fe299ad

1 file changed

Lines changed: 4 additions & 4 deletions

File tree

lambda/dynamodb/code/LambdaChatDynamoDB.js

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,7 @@ exports.handler = function(event, context) {
4949
},
5050
"Limit": 20,
5151
"ScanIndexForward": false
52-
}
52+
}
5353
console.log("Scanning the table");
5454
ddb.query(params, next);
5555
},
@@ -64,11 +64,11 @@ exports.handler = function(event, context) {
6464
ii = response.Items[i];
6565
var message = {};
6666
message['id'] = ii.message_id['S'];
67-
message['name'] = ii.name['S'];
67+
message['name'] = escapeHtml(ii.name['S']);
6868
message['message'] = escapeHtml(ii.message['S']);
6969
message['channel'] = ii.channel['S'];
7070
messageData.messages.push(message);
71-
}
71+
}
7272
next(null, JSON.stringify(messageData));
7373
},
7474
function savetos3(jsonstring, next) {
@@ -88,5 +88,5 @@ exports.handler = function(event, context) {
8888
}
8989
context.done(err, '');
9090
});
91-
91+
9292
};

0 commit comments

Comments
 (0)