Escape returned HTML.
This commit is contained in:
@@ -356,7 +356,7 @@ class OperationView extends Backbone.View
|
|||||||
code = $('<code />').text(@formatXml(content))
|
code = $('<code />').text(@formatXml(content))
|
||||||
pre = $('<pre class="xml" />').append(code)
|
pre = $('<pre class="xml" />').append(code)
|
||||||
else if contentType is "text/html"
|
else if contentType is "text/html"
|
||||||
code = $('<code />').html(content)
|
code = $('<code />').html(_.escape(content))
|
||||||
pre = $('<pre class="xml" />').append(code)
|
pre = $('<pre class="xml" />').append(code)
|
||||||
else if /^image\//.test(contentType)
|
else if /^image\//.test(contentType)
|
||||||
pre = $('<img>').attr('src',url)
|
pre = $('<img>').attr('src',url)
|
||||||
|
|||||||
Reference in New Issue
Block a user