Merge pull request #589 from davidcole/escape_returned_html

Escape returned HTML
This commit is contained in:
Tony Tam
2014-09-20 13:45:20 -07:00

View File

@@ -356,7 +356,7 @@ class OperationView extends Backbone.View
code = $('<code />').text(@formatXml(content)) code = $('<code />').text(@formatXml(content))
pre = $('<pre class="xml" />').append(code) pre = $('<pre class="xml" />').append(code)
else if contentType is "text/html" else if contentType is "text/html"
code = $('<code />').html(content) code = $('<code />').html(_.escape(content))
pre = $('<pre class="xml" />').append(code) pre = $('<pre class="xml" />').append(code)
else if /^image\//.test(contentType) else if /^image\//.test(contentType)
pre = $('<img>').attr('src',url) pre = $('<img>').attr('src',url)