We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Book titles like https://tools.wmflabs.org/sqid/#/view?id=Q43981055 show some Javascript popup, this shouldn't be possible and is quite some security issue.
The text was updated successfully, but these errors were encountered:
Note that Q4115189 can best be used to test this. I already inserted some HTML entities there and we can see a lack of escaping. The current behaviour suggests that a simple escaping alon ghte lines of https://stackoverflow.com/questions/6234773/can-i-escape-html-special-chars-in-javascript when applied ot all strings before output would work correctly.
Sorry, something went wrong.
Correctly escape HTML in labels & values
57e9e3b
Fixes #127.
e90e0ef
22617c2
f1f6820
mmarx
No branches or pull requests
Book titles like https://tools.wmflabs.org/sqid/#/view?id=Q43981055 show some Javascript popup, this shouldn't be possible and is quite some security issue.
The text was updated successfully, but these errors were encountered: