You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
All HTML escaping systems escape <, >, &, ', and ". The Handlebars docs say it also escapes , and a glance at the code suggests is escapes not only but also =. So it seems like the docs are wrong? Also, why escape ``` or =?
The text was updated successfully, but these errors were encountered:
Yeah, I almost mentioned that I could see that escaping = seems like it would make it much less likely that forgetting to quote attribute values would lead to an exploit. But what is the ``` issue?
Yep, this article confirms that IE (at least through version 10, which was current when it was written) will treat ``` as a quoting character like ' and `"`.
All HTML escaping systems escape
<
,>
,&
,'
, and"
. The Handlebars docs say it also escapes, and a glance at the code suggests is escapes not only
but also=
. So it seems like the docs are wrong? Also, why escape ``` or=
?The text was updated successfully, but these errors were encountered: