Merge pull request #589 from davidcole/escape_returned_html
Escape returned HTML
This commit is contained in:
@@ -356,7 +356,7 @@ class OperationView extends Backbone.View
|
||||
code = $('<code />').text(@formatXml(content))
|
||||
pre = $('<pre class="xml" />').append(code)
|
||||
else if contentType is "text/html"
|
||||
code = $('<code />').html(content)
|
||||
code = $('<code />').html(_.escape(content))
|
||||
pre = $('<pre class="xml" />').append(code)
|
||||
else if /^image\//.test(contentType)
|
||||
pre = $('<img>').attr('src',url)
|
||||
|
||||
Reference in New Issue
Block a user