Keep one escapeHTML, and make it safe in an attribute

There were two: the one in dom_helpers escaped through a text node, which
leaves double quotes alone, so it could not have closed the hole in the
link preview's img src.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0186eyzivcTn6wqjEE4Wnxdt
This commit is contained in:
Rosa Gutierrez
2026-09-11 16:29:29 +02:00
committed by Rosa Gutierrez
parent e6022a52c3
commit 8722057545
3 changed files with 2 additions and 8 deletions
+1 -1
View File
@@ -9,5 +9,5 @@ export function truncateString(string, length, omission = "…") {
}
export function escapeHTML(string) {
return String(string).replace(/[&<>"']/g, character => HTML_ESCAPES[character])
return String(string ?? "").replace(/[&<>"']/g, character => HTML_ESCAPES[character])
}