Revert "Escape = in HTML content"
This reverts commit 1c863e34, a change that was illegal in a patch (by semver semantics).
see #1489
This commit is contained in:
committed by
Nils Knappmeier
parent
af919d2348
commit
6e9dbac8e9
@@ -4,12 +4,13 @@ const escape = {
|
|||||||
'>': '>',
|
'>': '>',
|
||||||
'"': '"',
|
'"': '"',
|
||||||
"'": ''',
|
"'": ''',
|
||||||
'`': '`',
|
'`': '`'
|
||||||
'=': '='
|
// The "equals-sign" is intentionally excluded from this list
|
||||||
|
// due to semantic-versioning issues (see #1489)
|
||||||
};
|
};
|
||||||
|
|
||||||
const badChars = /[&<>"'`=]/g,
|
const badChars = /[&<>"'`]/g,
|
||||||
possible = /[&<>"'`=]/;
|
possible = /[&<>"'`]/;
|
||||||
|
|
||||||
function escapeChar(chr) {
|
function escapeChar(chr) {
|
||||||
return escape[chr];
|
return escape[chr];
|
||||||
|
|||||||
+3
-1
@@ -18,7 +18,9 @@ describe('utils', function() {
|
|||||||
describe('#escapeExpression', function() {
|
describe('#escapeExpression', function() {
|
||||||
it('shouhld escape html', function() {
|
it('shouhld escape html', function() {
|
||||||
equals(Handlebars.Utils.escapeExpression('foo<&"\'>'), 'foo<&"'>');
|
equals(Handlebars.Utils.escapeExpression('foo<&"\'>'), 'foo<&"'>');
|
||||||
equals(Handlebars.Utils.escapeExpression('foo='), 'foo=');
|
});
|
||||||
|
it('should not escape the equals-sign in 3.x (#1489)', function() {
|
||||||
|
equals(Handlebars.Utils.escapeExpression('foo='), 'foo=');
|
||||||
});
|
});
|
||||||
it('should not escape SafeString', function() {
|
it('should not escape SafeString', function() {
|
||||||
var string = new Handlebars.SafeString('foo<&"\'>');
|
var string = new Handlebars.SafeString('foo<&"\'>');
|
||||||
|
|||||||
Reference in New Issue
Block a user