|
74 | 74 | schemaName: 'blast', |
75 | 75 | queryName: 'blast_jobs', |
76 | 76 | filterArray: [ |
77 | | - LABKEY.Filter.create('objectid', <%=q(job.getObjectid())%>, LABKEY.Filter.Types.EQUAL) |
| 77 | + LABKEY.Filter.create('objectid', <%=q(h(job.getObjectid()))%>, LABKEY.Filter.Types.EQUAL) |
78 | 78 | ] |
79 | 79 | } |
80 | 80 | },{ |
81 | 81 | html: '<hr>' |
82 | 82 | },{ |
83 | 83 | layout: 'hbox', |
84 | 84 | border: false, |
85 | | - hidden: !<%=hasRun%>, |
| 85 | + hidden: !<%=h(hasRun)%>, |
86 | 86 | items: [{ |
87 | 87 | xtype: 'combo', |
88 | 88 | fieldLabel: 'Choose Output Format', |
|
92 | 92 | valueField: 'id', |
93 | 93 | labelWidth: 150, |
94 | 94 | width: 600, |
95 | | - value: <%=q(outputFormat == null ? null : outputFormat.name())%>, |
| 95 | + value: <%=q(h(outputFormat == null ? null : outputFormat.name()))%>, |
96 | 96 | store: { |
97 | 97 | type: 'array', |
98 | 98 | fields: ['label', 'id'], |
|
123 | 123 | return; |
124 | 124 | } |
125 | 125 |
|
126 | | - window.location = LABKEY.ActionURL.buildURL('blast', 'jobDetails', null, {outputFmt: fmt, jobId: <%=q(job.getObjectid())%>}); |
| 126 | + window.location = LABKEY.ActionURL.buildURL('blast', 'jobDetails', null, {outputFmt: fmt, jobId: <%=q(h(job.getObjectid()))%>}); |
127 | 127 | } |
128 | 128 | },{ |
129 | 129 | xtype: 'button', |
|
139 | 139 | var newForm = Ext4.DomHelper.append(document.getElementsByTagName('body')[0], |
140 | 140 | '<form method="POST" action="' + LABKEY.ActionURL.buildURL("blast", "downloadBlastResults") + '">' + |
141 | 141 | '<input type="hidden" name="fileName" value="' + Ext4.htmlEncode('blastResults.txt') + '" />' + |
142 | | - '<input type="hidden" name="jobId" value="' + <%=q(job.getObjectid())%> + '" />' + |
| 142 | + '<input type="hidden" name="jobId" value="' + <%=q(h(job.getObjectid()))%> + '" />' + |
143 | 143 | '<input type="hidden" name="outputFormat" value="' + fmt + '" />' + |
144 | 144 | '</form>'); |
145 | 145 | newForm.submit(); |
|
164 | 164 |
|
165 | 165 | getResultItems: function(){ |
166 | 166 | var ret = []; |
167 | | - if (!<%=hasRun%>){ |
| 167 | + if (!<%=h(hasRun)%>){ |
168 | 168 | ret.push({ |
169 | 169 | xtype: 'panel', |
170 | 170 | minHeight: 200, |
|
191 | 191 |
|
192 | 192 | Ext4.create('BLAST.panel.BlastDetailsPanel', { |
193 | 193 |
|
194 | | - }).render(<%=q(renderTarget)%>); |
| 194 | + }).render(<%=q(h(renderTarget))%>); |
195 | 195 | }); |
196 | 196 |
|
197 | 197 | </script> |
198 | 198 |
|
199 | | -<div id=<%=q(renderTarget)%>></div> |
200 | | -<div id=<%=q(renderTarget + "_results")%>> |
| 199 | +<div id=<%=q(h(renderTarget))%>></div> |
| 200 | +<div id=<%=q(h(renderTarget + "_results"))%>> |
201 | 201 | <% |
202 | 202 | if (job.isHasRun()) |
203 | 203 | { |
|
0 commit comments