Skip to content

variantopedia: use escapejs for values in inline JS string literals#1636

Open
davmlaw wants to merge 1 commit into
masterfrom
hardening/variantopedia-escapejs
Open

variantopedia: use escapejs for values in inline JS string literals#1636
davmlaw wants to merge 1 commit into
masterfrom
hardening/variantopedia-escapejs

Conversation

@davmlaw

@davmlaw davmlaw commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

🤖 Written by Claude

Switch the two values embedded in inline <script> string literals in variant_details.html from |safe to |escapejs, so they are always correctly encoded for a JavaScript-string context regardless of their source. No visible change for current data.

Switch the two values embedded in inline <script> string literals in variant_details.html
from |safe to |escapejs so they are correctly encoded for a JS-string context.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant