From 88946d331aad96ecbdf9d570853121e5a7eb07ab Mon Sep 17 00:00:00 2001 From: Anders Kaseorg Date: Fri, 20 Jan 2017 13:13:31 -0500 Subject: Replace all setTimeout strings with functions This fixes a cross-site scripting vulnerability. Signed-off-by: Anders Kaseorg --- js/feedlist.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'js/feedlist.js') diff --git a/js/feedlist.js b/js/feedlist.js index c98cfaab5..e66a0c1b6 100644 --- a/js/feedlist.js +++ b/js/feedlist.js @@ -198,7 +198,7 @@ function feedlist_init() { loading_set_progress(50); document.onkeydown = hotkey_handler; - setTimeout("hotkey_prefix_timeout()", 5*1000); + setTimeout(hotkey_prefix_timeout, 5*1000); if (!getActiveFeedId()) { viewfeed({feed: -3}); -- cgit v1.2.3-54-g00ecf