better sanitize jsonp

This commit is contained in:
Robert Helmer 2018-01-30 12:52:19 -08:00
parent d7c93b0c0d
commit f56936c936
2 changed files with 3 additions and 2 deletions

View file

@ -18,7 +18,7 @@ var apiCaller = function(req, res, fields) {
apiLogger.info("RESPONSE, " + req.params.func + ", " + response);
//is this a jsonp call, if yes, add the function call
if(req.query.jsonp)
if(req.query.jsonp && isVarName(response))
response = req.query.jsonp + "(" + response + ")";
res._____send(response);