biocore/empress

When setting text in the DOM, use textContent instead of innerHTML

オープン

#216 opened on 2020/06/26

 (0 件のコメント) (1 件のリアクション) (0 人の担当者)JavaScript (32 件のフォーク)auto 404
good first issuerefactoring

Repository metrics

Stars
 (56 個のスター)
PR merge metrics
 (PR metrics pending)

説明

See the MDN docs on some of the downsides of setting things with innerHTML here.

This shouldn't be a huge problem since Empress visualizations are (as of writing) inherently client-side applications, but there's the potential for users to break things if their data includes bizarre names -- for example, a metadata column is named <b>i'm a problematic metadata column</b>, or something silly like that. (Also, more realistically, backslashes or ampersands might also cause problems with innerHTML.)

コントリビューターガイド