Skip to content

Grabbing the text unescapes any escaped html. Grab the html. - #30

Open
darfire wants to merge 1 commit into
vestman:masterfrom
darfire:unescape-bug
Open

Grabbing the text unescapes any escaped html. Grab the html.#30
darfire wants to merge 1 commit into
vestman:masterfrom
darfire:unescape-bug

Conversation

@darfire

@darfire darfire commented Mar 9, 2015

Copy link
Copy Markdown

Try having the text of an option element as something like &lt;script&gt;alert(11)&lt;/script&gt; (<script>alert(11)</script> escaped). When you take $optionText with text() you get the unescaped content. When you set it later on the span.sod_option using html() you're basically undoing the escaping. This fixes it by keeping the escaped content.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant