File tree Expand file tree Collapse file tree 1 file changed +12
-2
lines changed
sde_indexing_helper/static/js Expand file tree Collapse file tree 1 file changed +12
-2
lines changed Original file line number Diff line number Diff line change @@ -1208,12 +1208,22 @@ function getCuratedScrapedTitleColumn() {
1208
1208
} ;
1209
1209
}
1210
1210
1211
+ function escapeHtml ( str ) {
1212
+ if ( ! str ) return '' ;
1213
+ return str
1214
+ . replace ( / & / g, '&' )
1215
+ . replace ( / < / g, '<' )
1216
+ . replace ( / > / g, '>' )
1217
+ . replace ( / " / g, '"' )
1218
+ . replace ( / ' / g, ''' ) ;
1219
+ }
1220
+
1211
1221
function getGeneratedTitleColumn ( ) {
1212
1222
return {
1213
1223
data : "generated_title" ,
1214
1224
width : "20%" ,
1215
1225
render : function ( data , type , row ) {
1216
- return `<input type="text" class="form-control individual_title_input whiteText" value=' ${ data } ' data-generated-title-id=${ row [ "generated_title_id" ]
1226
+ return `<input type="text" class="form-control individual_title_input whiteText" value=" ${ escapeHtml ( data ) } " data-generated-title-id=${ row [ "generated_title_id" ]
1217
1227
} data-match-pattern-type=${ row [ "match_pattern_type" ]
1218
1228
} data-delta-urls-count=${ row [ "delta_urls_count" ]
1219
1229
} data-url=${ remove_protocol ( row [ "url" ] ) } />`;
@@ -1226,7 +1236,7 @@ function getCuratedGeneratedTitleColumn() {
1226
1236
data : "generated_title" ,
1227
1237
width : "20%" ,
1228
1238
render : function ( data , type , row ) {
1229
- return `<input type="text" class="form-control individual_title_input whiteText" value=' ${ data } ' data-generated-title-id=${ row [ "generated_title_id" ]
1239
+ return `<input type="text" class="form-control individual_title_input whiteText" value=" ${ escapeHtml ( data ) } " data-generated-title-id=${ row [ "generated_title_id" ]
1230
1240
} data-match-pattern-type=${ row [ "match_pattern_type" ]
1231
1241
} data-curated-urls-count=${ row [ "curated_urls_count" ]
1232
1242
} data-url=${ remove_protocol ( row [ "url" ] ) } />`;
You can’t perform that action at this time.
0 commit comments