Uploaded image for project: 'Click'
  1. Click
  2. CLK-674

Escape control values as xml entities instead of html

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 2.2.0
    • 2.3.0-M1
    • core
    • None

    Description

      Click escapes Control values and attributes using HTML entities, which doesn't play nice when returning XML payloads for Ajax requests.

      I suggest we only escape dangerous HTML characters > < " ' &, with the option of switching escaping off.

      Is there any reason to escape all HTML entities?

      PS: Apostrophe should be escaped as "& #039;" not "& apos;". apos is not a valid HTML entity

      Attachments

        Activity

          People

            sabob Bob Schellink
            sabob Bob Schellink
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: