Преглед на файлове

found a better JS html entity escape function and use it to fix regression introduced by the preview feature, resolves #43

El RIDO преди 10 години
родител
ревизия
97ed1a5cf4
променени са 1 файла, в които са добавени 31 реда и са изтрити 12 реда
  1. 31 12
      js/privatebin.js

+ 31 - 12
js/privatebin.js

@@ -130,17 +130,6 @@ $(function() {
             }
             }
         },
         },
 
 
-        /**
-         * Convert all applicable characters to HTML entities
-         *
-         * @param string str
-         * @return string encoded string
-         */
-        htmlEntities: function(str)
-        {
-            return String(str).replace(/&/g, '&amp;').replace(/</g, '&lt;').replace(/>/g, '&gt;').replace(/"/g, '&quot;');
-        },
-
         /**
         /**
          * Text range selection.
          * Text range selection.
          * From: https://stackoverflow.com/questions/985272/jquery-selecting-text-in-an-element-akin-to-highlighting-with-your-mouse
          * From: https://stackoverflow.com/questions/985272/jquery-selecting-text-in-an-element-akin-to-highlighting-with-your-mouse
@@ -301,6 +290,34 @@ $(function() {
                 }
                 }
             }
             }
             return '';
             return '';
+        },
+
+        /**
+         * Convert all applicable characters to HTML entities.
+         * From: https://github.com/janl/mustache.js/blob/master/mustache.js#L60
+         *
+         * @param string str
+         * @return string escaped HTML
+         */
+        htmlEntities: function(str) {
+            return String(str).replace(
+                /[&<>"'`=\/]/g, function(s) {
+                    return helper.entityMap[s];
+                });
+        },
+
+        /**
+         * character to HTML entity lookup table
+         */
+        entityMap: {
+            '&': '&amp;',
+            '<': '&lt;',
+            '>': '&gt;',
+            '"': '&quot;',
+            "'": '&#39;',
+            '/': '&#x2F;',
+            '`': '&#x60;',
+            '=': '&#x3D;'
         }
         }
     };
     };
 
 
@@ -635,7 +652,9 @@ $(function() {
                             prettyPrint();
                             prettyPrint();
                         }
                         }
                         this.prettyPrint.html(
                         this.prettyPrint.html(
-                            prettyPrintOne(text, null, true)
+                            prettyPrintOne(
+                                helper.htmlEntities(text), null, true
+                            )
                         );
                         );
                     }
                     }
                     // fall through, as the rest is the same
                     // fall through, as the rest is the same