From a6c286b0f2e6bed2bab671f282fbcbdb455dcb10 Mon Sep 17 00:00:00 2001 From: Risto Lahtela <24460436+Rsl1122@users.noreply.github.com> Date: Sun, 24 Jan 2021 11:05:04 +0200 Subject: [PATCH] Prevented a future accidental XSS vulnerability in Graph type selection The type parameter was passed to an exception that is currently turned into json, but in the future the way this exception is handled could have changed. --- .../delivery/webserver/resolver/json/GraphsJSONResolver.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Plan/common/src/main/java/com/djrapitops/plan/delivery/webserver/resolver/json/GraphsJSONResolver.java b/Plan/common/src/main/java/com/djrapitops/plan/delivery/webserver/resolver/json/GraphsJSONResolver.java index 7588b82ef..cb78e4aea 100644 --- a/Plan/common/src/main/java/com/djrapitops/plan/delivery/webserver/resolver/json/GraphsJSONResolver.java +++ b/Plan/common/src/main/java/com/djrapitops/plan/delivery/webserver/resolver/json/GraphsJSONResolver.java @@ -109,7 +109,7 @@ public class GraphsJSONResolver implements Resolver { case "serverPie": return DataID.GRAPH_SERVER_PIE; default: - throw new BadRequestException("unknown 'type' parameter: " + type); + throw new BadRequestException("unknown 'type' parameter."); } }