fix: delete script — assign JSON-safe name to JS var, no \n in string, no inline concat

This commit is contained in:
yumoqing 2026-08-05 18:12:27 +08:00
parent c0c5ba831f
commit ee4bf7548a

View File

@ -16,8 +16,7 @@ async with get_sor_context(env, 'rag') as sor:
engine = r.embedding_engine or "CLIP"
idstr = str(r.id)
namestr = r.name or ''
# Escape for JS single-quoted string: backslash, single quote, newline, carriage return
js_name = namestr.replace("\\", "\\\\").replace("'", "\\'").replace("\n", "\\n").replace("\r", "\\r")
safe_name = json.dumps(namestr, ensure_ascii=False)
cards.append({
"widgettype": "VBox",
"options": {"cwidth": 16, "cheight": 12, "bgcolor": "#f0f7ff", "padding": "12px",
@ -53,7 +52,8 @@ async with get_sor_context(env, 'rag') as sor:
"padding": "2px 8px", "borderRadius": "4px", "bgcolor": "#fee"},
"binds": [{"wid": "self", "event": "click", "actiontype": "script",
"script": "event.stopPropagation();"
"if(!confirm('\u786e\u8ba4\u5220\u9664\u77e5\u8bc6\u5e93\u300c" + js_name + "\u300d\uff1f\n\n\u8be5\u64cd\u4f5c\u4f1a\u5220\u9664\u77e5\u8bc6\u5e93\u5185\u6240\u6709\u6587\u4ef6\u3001\u6807\u7b7e\u548c\u6570\u636e\uff0c\u4e0d\u53ef\u6062\u590d\uff01'))return;"
"var nm=" + safe_name + ";"
"if(!confirm('\u786e\u8ba4\u5220\u9664\u77e5\u8bc6\u5e93\u300c'+nm+'\u300d\uff1f \u6b64\u64cd\u4f5c\u4e0d\u53ef\u6062\u590d\uff01'))return;"
"fetch('/rag/knowledge_bases_list/delete_kb.dspy?kb_id=" + idstr + "').then(function(r){return r.json()}).then(function(d){"
"if(d.status==='error'){alert('\u5220\u9664\u5931\u8d25\uff1a'+d.error);return;}"
"window.location.href='/rag/knowledge_bases_list/index.ui';"