Wrapper escape apos characters

This commit is contained in:
shortcutme 2018-03-06 12:01:39 +01:00
parent e96dd14e0d
commit 9dabd1f344
No known key found for this signature in database
GPG key ID: 5B63BAE6CB9613AE

View file

@ -531,7 +531,7 @@ class Wrapper
if value instanceof Array if value instanceof Array
value = @toHtmlSafe(value) value = @toHtmlSafe(value)
else else
value = String(value).replace(/&/g, '&amp;').replace(/</g, '&lt;').replace(/>/g, '&gt;').replace(/"/g, '&quot;') # Escape value = String(value).replace(/&/g, '&amp;').replace(/</g, '&lt;').replace(/>/g, '&gt;').replace(/"/g, '&quot;').replace(/'/g, '&apos;') # Escape dangerous characters
value = value.replace(/&lt;([\/]{0,1}(br|b|u|i|small))&gt;/g, "<$1>") # Unescape b, i, u, br tags value = value.replace(/&lt;([\/]{0,1}(br|b|u|i|small))&gt;/g, "<$1>") # Unescape b, i, u, br tags
values[i] = value values[i] = value
return values return values