Skip to content

Commit ea8fa6c

Browse files
authored
Merge pull request #351 from GOKULRAJ136/MOSIP-36172
Security hotspot fix [MOSIP-37914]
2 parents 3929305 + 60937e7 commit ea8fa6c

File tree

1 file changed

+3
-5
lines changed

1 file changed

+3
-5
lines changed

admin-ui/src/app/features/download-card/download-card/download-card.component.ts

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,10 @@
1-
import { Component, OnInit } from '@angular/core';
1+
import { Component, OnInit, Sanitizer, SecurityContext } from '@angular/core';
22
import { TranslateService } from '@ngx-translate/core';
33
import { AppConfigService } from 'src/app/app-config.service';
44
import { AuditService } from 'src/app/core/services/audit.service';
55
import { DataStorageService } from 'src/app/core/services/data-storage.service';
66
import { MatDialog } from '@angular/material/dialog';
77
import { DialogComponent } from 'src/app/shared/dialog/dialog.component';
8-
import { DomSanitizer } from '@angular/platform-browser';
98
import { saveAs } from 'file-saver';
109
import { ActivatedRoute, Router, NavigationEnd } from '@angular/router';
1110
import { HttpErrorResponse } from '@angular/common/http';
@@ -38,7 +37,7 @@ export class DownloadCardComponent implements OnInit {
3837
private activatedRoute: ActivatedRoute,
3938
private dataStorageService: DataStorageService,
4039
public dialog: MatDialog,
41-
private sanitizer:DomSanitizer,
40+
private sanitizer: Sanitizer,
4241
private router: Router
4342
) {
4443
translate.use(appService.getConfig().primaryLangCode);
@@ -81,8 +80,7 @@ export class DownloadCardComponent implements OnInit {
8180
}
8281

8382
renderImage(){
84-
const trustedUrl = this.sanitizer.bypassSecurityTrustResourceUrl(this.data.applicantPhoto);
85-
this.applicantPhoto = trustedUrl;
83+
this.applicantPhoto = this.sanitizer.sanitize(SecurityContext.URL, this.data.applicantPhoto);
8684
}
8785

8886
search() {

0 commit comments

Comments
 (0)