Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

fix: escape a single quote#313

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Open
yusukebe wants to merge3 commits intopreactjs:main
base:main
Choose a base branch
Loading
fromyusukebe:escape-single-quote

Conversation

@yusukebe
Copy link

Hi,

Firstly, thank you for the great project.

In this PR, I've implemented the escaping of a single quote (0x27) to'. This modification will prevent the potential execution of scripts, as illustrated below:

constvalue="alert('bar!')";return<divonMouseOver={value}>foo</div>;

udleinati reacted with thumbs up emoji
@changeset-bot
Copy link

changeset-botbot commentedAug 13, 2023
edited
Loading

🦋 Changeset detected

Latest commit:345fcc7

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
preact-render-to-stringMajor

Not sure what this means?Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@marvinhagemeister
Copy link
Member

FYI: This is a breaking change. A a good chunk of users from theFresh framework depend on this working.

@yusukebe
Copy link
Author

Hi@marvinhagemeister,

I'm aware that Preact is used for Fresh, and I a fan of it. Indeed, this change introduces a breaking change that could have a significant impact. I believe it would be best to include this change when this package is released with a major version upgrade.

Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

@rschristianrschristianrschristian left review comments

At least 1 approving review is required to merge this pull request.

Assignees

No one assigned

Labels

None yet

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

3 participants

@yusukebe@marvinhagemeister@rschristian

[8]ページ先頭

©2009-2025 Movatter.jp