Skip to content

Commit fb3e243

Browse files
Merge pull request #780 from alphagov/fix-html-injection-ajax-example
2 parents 1d5c175 + d905dfe commit fb3e243

File tree

3 files changed

+4
-5
lines changed

3 files changed

+4
-5
lines changed

examples/ajax-source.html

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -292,8 +292,7 @@ <h1>Accessible Autocomplete AJAX source example</h1>
292292
var submittedEl = document.querySelector('.submitted')
293293
submittedEl.classList.remove('submitted--hidden')
294294
var params = new URLSearchParams(document.location.search.split('?')[1])
295-
document.querySelector('.submitted__last-location').innerHTML = params.get('last-location')
296-
document.querySelector('.submitted__passport-location').innerHTML = params.get('passport-location')
295+
document.querySelector('.submitted__last-location').textContent = params.get('last-location')
297296
}
298297
</script>
299298
</body>

examples/form-single.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -374,7 +374,7 @@ <h1>Accessible Autocomplete single field form example</h1>
374374
var submittedEl = document.querySelector('.submitted')
375375
submittedEl.classList.remove('submitted--hidden')
376376
var params = new URLSearchParams(document.location.search.split('?')[1])
377-
document.querySelector('.submitted__last-location').innerHTML = params.get('last-location')
377+
document.querySelector('.submitted__last-location').textContent = params.get('last-location')
378378
}
379379
</script>
380380
</body>

examples/form.html

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -665,8 +665,8 @@ <h1>Accessible Autocomplete form example</h1>
665665
var submittedEl = document.querySelector('.submitted')
666666
submittedEl.classList.remove('submitted--hidden')
667667
var params = new URLSearchParams(document.location.search.split('?')[1])
668-
document.querySelector('.submitted__last-location').innerHTML = params.get('last-location')
669-
document.querySelector('.submitted__passport-location').innerHTML = params.get('passport-location')
668+
document.querySelector('.submitted__last-location').textContent = params.get('last-location')
669+
document.querySelector('.submitted__passport-location').textContent = params.get('passport-location')
670670
}
671671
</script>
672672
</body>

0 commit comments

Comments
 (0)