fix(storefront): BCTHEME-1985 Fix stored XSS within company address field #2485
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What?
In the address-list.html field, the the company field should be {{}} rather than {{{}}} to prevent an XSS attack
Tickets/Documentation
Requirements
Screenshots
Before:
![image](https://private-user-images.githubusercontent.com/98066605/370108368-ee868faf-a728-4902-85a2-f2fcf498f561.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MzkyNDg2NTksIm5iZiI6MTczOTI0ODM1OSwicGF0aCI6Ii85ODA2NjYwNS8zNzAxMDgzNjgtZWU4NjhmYWYtYTcyOC00OTAyLTg1YTItZjJmY2Y0OThmNTYxLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMTElMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjExVDA0MzIzOVomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTRlNzI2NTViMjYyOGM3ZmY2ZjUyNTQ1MzExYTc0ODE2MWFiOTAxZTE5MDFjODJhMzk3ZjRjMWUwYTdmMDUxZmImWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.sKDeOSSZjQe2Ogwa7RgPnOLhLHP9NEOUXNeERIlakxM)
After:
![image](https://private-user-images.githubusercontent.com/98066605/370108535-2c1d6fd4-52e4-4a31-a88a-d77be07039d3.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MzkyNDg2NTksIm5iZiI6MTczOTI0ODM1OSwicGF0aCI6Ii85ODA2NjYwNS8zNzAxMDg1MzUtMmMxZDZmZDQtNTJlNC00YTMxLWE4OGEtZDc3YmUwNzAzOWQzLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMTElMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjExVDA0MzIzOVomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTUyNjNhMzdlYzQ3MjUzNTRhNjhmMTcyOTQ4ZDFhMzNjYzE1OTE2YjMzMGE4MjQ1NmQ2Njg5MjMxMTQ1YzZlOWEmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0._O7pzrGNo5Zrao3MNmMzogUAOMyts9G8T0MDFm5OEzU)