BUGFIX #24: toggle_string arguments are now escaped before being inserted into the DOM.

This commit is contained in:
n1474335 2016-11-30 19:33:20 +00:00
parent 09d515cbae
commit 2f0bc54046
5 changed files with 12 additions and 11 deletions

File diff suppressed because one or more lines are too long

File diff suppressed because one or more lines are too long

File diff suppressed because one or more lines are too long

View File

@ -436,7 +436,8 @@ HTMLApp.prototype.set_recipe_config = function(recipe_config) {
} else if (args[j].classList.contains("toggle-string")) {
// toggle_string
args[j].value = recipe_config[i].args[j].string;
args[j].previousSibling.children[0].innerHTML = recipe_config[i].args[j].option +
args[j].previousSibling.children[0].innerHTML =
Utils.escape_html(recipe_config[i].args[j].option) +
" <span class='caret'></span>";
} else {
// all others

View File

@ -1,9 +1,9 @@
202 source files
104190 lines
104191 lines
4.0M size
136 JavaScript source files
95118 lines
95119 lines
3.4M size
78 third party JavaScript source files
@ -11,7 +11,7 @@
2.7M size
58 first party JavaScript source files
18741 lines
18742 lines
724K size
3.1M uncompressed JavaScript size