Keep one escapeHTML, and make it safe in an attribute

There were two: the one in dom_helpers escaped through a text node, which
leaves double quotes alone, so it could not have closed the hole in the
link preview's img src.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0186eyzivcTn6wqjEE4Wnxdt
This commit is contained in:
Rosa Gutierrez
2026-09-11 16:29:29 +02:00
committed by Rosa Gutierrez
parent e6022a52c3
commit 8722057545
3 changed files with 2 additions and 8 deletions
@@ -1,7 +1,7 @@
import { Controller } from "@hotwired/stimulus"
import FileUploader from "models/file_uploader"
import { onNextEventLoopTick, nextFrame } from "helpers/timing_helpers"
import { escapeHTML } from "helpers/dom_helpers"
import { escapeHTML } from "helpers/string_helpers"
export default class extends Controller {
static classes = ["toolbar"]
-6
View File
@@ -4,12 +4,6 @@ export function scrollToBottom(container) {
container.scrollTop = container.scrollHeight
}
export function escapeHTML(html) {
const div = document.createElement("div")
div.textContent = html
return div.innerHTML
}
export function parseHTMLFragment(html) {
const template = document.createElement("template")
template.innerHTML = html
+1 -1
View File
@@ -9,5 +9,5 @@ export function truncateString(string, length, omission = "…") {
}
export function escapeHTML(string) {
return String(string).replace(/[&<>"']/g, character => HTML_ESCAPES[character])
return String(string ?? "").replace(/[&<>"']/g, character => HTML_ESCAPES[character])
}