Open taoeffect opened 3 months ago
I just noticed this is a more widespread problem in the codebase
Is the screenshot in #2051 another example?
Is the screenshot in https://github.com/okTurtles/group-income/issues/2051 another example?
Yeah that could be another thing to boy-scout for this issue 👍
Problem
In #2069 I got this error:
This is clearly a problematic prompt as it shows HTML to the user instead of rendering it:
EDIT: I just noticed this is a more widespread problem in the codebase, as this use of
alert
seems to exist in the contracts too:IMPORTANT: the use of
alert
by itself isn't a problem, but when the message contains HTML -gi.ui/prompt
must be used instead because only that can render it.Solution
alert
withgi.ui/prompt
Make 100% sure to test every
alert
that's replaced withgi.ui/prompt
to verify it displays correctly.If called from contracts,
gi.ui/prompt
will need to be whitelisted inmain.js
underallowedSelectors
.