prevent template injection
parent
f9490829af
commit
2c03ca70c2
|
@ -130,10 +130,14 @@ class UserTimelineItemTitle
|
||||||
_getLink: (url, text, title) ->
|
_getLink: (url, text, title) ->
|
||||||
title = title || text
|
title = title || text
|
||||||
|
|
||||||
|
span = $('<span>')
|
||||||
|
.attr('ng-non-bindable', true)
|
||||||
|
.text(text)
|
||||||
|
|
||||||
return $('<a>')
|
return $('<a>')
|
||||||
.attr('tg-nav', url)
|
.attr('tg-nav', url)
|
||||||
.text(text)
|
|
||||||
.attr('title', title)
|
.attr('title', title)
|
||||||
|
.append(span)
|
||||||
.prop('outerHTML')
|
.prop('outerHTML')
|
||||||
|
|
||||||
_getUsernameSpan: (text) ->
|
_getUsernameSpan: (text) ->
|
||||||
|
|
Loading…
Reference in New Issue