Keep one escapeHTML, and make it safe in an attribute

There were two: the one in dom_helpers escaped through a text node, which
leaves double quotes alone, so it could not have closed the hole in the
link preview's img src.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0186eyzivcTn6wqjEE4Wnxdt
This commit is contained in:
Rosa Gutierrez
2026-09-11 16:29:29 +02:00
committed by Rosa Gutierrez
parent e6022a52c3
commit 8722057545
3 changed files with 2 additions and 8 deletions
@@ -1,7 +1,7 @@
import { Controller } from "@hotwired/stimulus"
import FileUploader from "models/file_uploader"
import { onNextEventLoopTick, nextFrame } from "helpers/timing_helpers"
import { escapeHTML } from "helpers/dom_helpers"
import { escapeHTML } from "helpers/string_helpers"
export default class extends Controller {
static classes = ["toolbar"]