Skip to content

Escape labels in hover#464

Merged
JelteF merged 1 commit into
morrisjs:masterfrom
JelteF:escape-hover
Oct 15, 2014
Merged

Escape labels in hover#464
JelteF merged 1 commit into
morrisjs:masterfrom
JelteF:escape-hover

Conversation

@JelteF
Copy link
Copy Markdown
Contributor

@JelteF JelteF commented Jul 16, 2014

Prevents XSS attacks by not concatenating the row label. The row label could contain any value. I'm comparing stats of users for instance, so this wouldn't be safe.

JelteF added a commit that referenced this pull request Oct 15, 2014
@JelteF JelteF merged commit 1c66cfc into morrisjs:master Oct 15, 2014
@Jamesking56
Copy link
Copy Markdown

Will this ever get deployed to NPM?

@dvetlugin
Copy link
Copy Markdown

npm i morrisjs/morris.js -s

@Jamesking56
Copy link
Copy Markdown

@dvetlugin that breaks npm audit for me with invalid tree

pierresh pushed a commit to pierresh/morris.js that referenced this pull request Jan 23, 2020
@pierresh
Copy link
Copy Markdown

Hello,

For your information, I have just applied this pull request in my fork.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants