浏览代码

(fix): Do not allow external css customization for static prejoin

This prevents CSS spoofing.
master
Vlad Piersec 4 年前
父节点
当前提交
f82d46337b
共有 1 个文件被更改,包括 0 次插入4 次删除
  1. 0
    4
      static/prejoin.html

+ 0
- 4
static/prejoin.html 查看文件

16
           const showAvatar = params.get('showAvatar') === 'true';
16
           const showAvatar = params.get('showAvatar') === 'true';
17
           const showJoinActions = params.get('showJoinActions') === 'true';
17
           const showJoinActions = params.get('showJoinActions') === 'true';
18
           const showSkipPrejoin = params.get('showSkipPrejoin') === 'true';
18
           const showSkipPrejoin = params.get('showSkipPrejoin') === 'true';
19
-          const css = params.get('style');
20
-          const style = document.createElement('style');
21
-          style.appendChild(document.createTextNode(css));
22
-          document.head.appendChild(style);
23
 
19
 
24
           JitsiMeetJS.app.renderEntryPoint({
20
           JitsiMeetJS.app.renderEntryPoint({
25
               Component: JitsiMeetJS.app.entryPoints.PREJOIN,
21
               Component: JitsiMeetJS.app.entryPoints.PREJOIN,

正在加载...
取消
保存