diff --git a/templates/application/display-block/block-chart-ajax-bars/layout.js.twig b/templates/application/display-block/block-chart-ajax-bars/layout.js.twig index dea9fb98d..0e071c641 100644 --- a/templates/application/display-block/block-chart-ajax-bars/layout.js.twig +++ b/templates/application/display-block/block-chart-ajax-bars/layout.js.twig @@ -61,7 +61,7 @@ if (typeof(charts) === "undefined") } var idxChart=charts.length; charts.push(chart); -var refreshChart{{ oUIBlock.sId|sanitize(constant('utils::ENUM_SANITIZATION_FILTER_VARIABLE_NAME')) }} = '$.post("{{ oUIBlock.sURLForRefresh|raw }}&refresh='+idxChart+'","", function (data) {'+ +var refreshChart{{ oUIBlock.sId|sanitize(constant('utils::ENUM_SANITIZATION_FILTER_VARIABLE_NAME')) }} = '$.post("{{ oUIBlock.sURLForRefresh|escape('js') }}&refresh='+idxChart+'","", function (data) {'+ 'charts['+idxChart+'].unload();'+ 'setTimeout(function () {eval(data.js);},50);'+ '})'; diff --git a/templates/application/display-block/block-chart-ajax-pie/layout.js.twig b/templates/application/display-block/block-chart-ajax-pie/layout.js.twig index 94c7144e8..91f9a926b 100644 --- a/templates/application/display-block/block-chart-ajax-pie/layout.js.twig +++ b/templates/application/display-block/block-chart-ajax-pie/layout.js.twig @@ -39,7 +39,7 @@ if (typeof (charts) === "undefined") } var idxChart = charts.length; charts.push(chart); -var refreshChart{{ oUIBlock.sId|sanitize(constant('utils::ENUM_SANITIZATION_FILTER_VARIABLE_NAME')) }}=' $.post("{{ oUIBlock.sURLForRefresh|raw }}&refresh='+idxChart+'","", function (data) {'+ +var refreshChart{{ oUIBlock.sId|sanitize(constant('utils::ENUM_SANITIZATION_FILTER_VARIABLE_NAME')) }}=' $.post("{{ oUIBlock.sURLForRefresh|escape('js')}}&refresh='+idxChart+'","", function (data) {'+ 'charts['+idxChart+'].unload();'+ 'setTimeout(function () {eval(data.js);},50);'+ '});'; diff --git a/templates/application/display-block/block-csv/layout.js.twig b/templates/application/display-block/block-csv/layout.js.twig index d3e0f6b45..84ba3fef4 100644 --- a/templates/application/display-block/block-csv/layout.js.twig +++ b/templates/application/display-block/block-csv/layout.js.twig @@ -2,7 +2,7 @@ {# @license http://opensource.org/licenses/AGPL-3.0 #} {% apply spaceless %} $.post( - '{{ oUIBlock.sAjaxLink|raw }}', + '{{ oUIBlock.sAjaxLink|escape('js') }}', {{ oUIBlock.sJsonParams|raw }}, function(data) { $('#csv_content').html(data);