Revert "Escape = in HTML content"
This reverts commit 1c863e34, a change that was illegal in a patch (by semver semantics).
see #1489
This commit is contained in:
committed by
Nils Knappmeier
parent
af919d2348
commit
6e9dbac8e9
@@ -4,12 +4,13 @@ const escape = {
|
||||
'>': '>',
|
||||
'"': '"',
|
||||
"'": ''',
|
||||
'`': '`',
|
||||
'=': '='
|
||||
'`': '`'
|
||||
// The "equals-sign" is intentionally excluded from this list
|
||||
// due to semantic-versioning issues (see #1489)
|
||||
};
|
||||
|
||||
const badChars = /[&<>"'`=]/g,
|
||||
possible = /[&<>"'`=]/;
|
||||
const badChars = /[&<>"'`]/g,
|
||||
possible = /[&<>"'`]/;
|
||||
|
||||
function escapeChar(chr) {
|
||||
return escape[chr];
|
||||
|
||||
+3
-1
@@ -18,7 +18,9 @@ describe('utils', function() {
|
||||
describe('#escapeExpression', function() {
|
||||
it('shouhld escape html', function() {
|
||||
equals(Handlebars.Utils.escapeExpression('foo<&"\'>'), 'foo<&"'>');
|
||||
equals(Handlebars.Utils.escapeExpression('foo='), 'foo=');
|
||||
});
|
||||
it('should not escape the equals-sign in 3.x (#1489)', function() {
|
||||
equals(Handlebars.Utils.escapeExpression('foo='), 'foo=');
|
||||
});
|
||||
it('should not escape SafeString', function() {
|
||||
var string = new Handlebars.SafeString('foo<&"\'>');
|
||||
|
||||
Reference in New Issue
Block a user