From f80c41058ca5ccfbf4c36984226698958a789635 Mon Sep 17 00:00:00 2001 From: Nick O'Leary Date: Thu, 17 Jul 2014 22:13:04 +0100 Subject: [PATCH] Properly escape html entities in debug Fixes #276 --- nodes/core/core/20-inject.html | 2 +- nodes/core/core/58-debug.html | 6 +++--- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/nodes/core/core/20-inject.html b/nodes/core/core/20-inject.html index e3e69efec..647a86227 100644 --- a/nodes/core/core/20-inject.html +++ b/nodes/core/core/20-inject.html @@ -400,7 +400,7 @@ }, button: { onclick: function() { - var label = (this.name||this.payload).replace(/&/g,"&").replace(//g,">"); + var label = (this.name||this.payload).replace(/&/g,"&").replace(//g,">"); d3.xhr("inject/"+this.id).post(function(err,resp) { if (err) { if (err.status == 404) { diff --git a/nodes/core/core/58-debug.html b/nodes/core/core/58-debug.html index ba3a0e498..82b2e80b7 100644 --- a/nodes/core/core/58-debug.html +++ b/nodes/core/core/58-debug.html @@ -150,9 +150,9 @@ } }; - var name = (o.name?o.name:o.id).toString().replace(/&/g,"&").replace(//g,">"); - var topic = (o.topic||"").toString().replace(/&/g,"&").replace(//g,">"); - var payload = (o.msg||"").toString().replace(/&/g,"&").replace(//g,">"); + var name = (o.name?o.name:o.id).toString().replace(/&/g,"&").replace(//g,">"); + var topic = (o.topic||"").toString().replace(/&/g,"&").replace(//g,">"); + var payload = (o.msg||"").toString().replace(/&/g,"&").replace(//g,">"); msg.className = 'debug-message'+(o.level?(' debug-message-level-'+o.level):'') msg.innerHTML = ''+getTimestamp()+''+ '['+name+']'+