-
Notifications
You must be signed in to change notification settings - Fork 651
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Sanitization issues in custom HTML infowindows #3010
Comments
@viddo is there a reason to now allow target and img tags with &? |
|
Sure, I won't share them publicly but: SB/4981277 -- they can be found in the first message. |
Example (target blank): https://team.cartodb.com/u/iriberri/viz/bb8a2cb4-dc52-11e4-bdcc-0e4fddd5de28/map |
The target issue will be solved here, CartoDB/carto.js#428 I'll reply to that thread on stackexchange, thx! Re: the img isssue far it seem to be an issue on embeds only for some reason, still investigating... |
The img-issue is due to the Mustache's escaping, using the unescaped output (triple angle brackets, i.e. |
Great, I'll let the users know. Thanks! |
Hey, people have reported a couple of issues these days when they use code inside their custom infowindows:
The text was updated successfully, but these errors were encountered: