biocore/empress
When setting text in the DOM, use textContent instead of innerHTML
開放
#216 建立於 2020年6月26日
good first issuerefactoring
倉庫指標
- 星標
- (56 顆星)
- PR 合併指標
- (30 天內沒有已合併 PR)
描述
See the MDN docs on some of the downsides of setting things with innerHTML here.
This shouldn't be a huge problem since Empress visualizations are (as of writing) inherently client-side applications, but there's the potential for users to break things if their data includes bizarre names -- for example, a metadata column is named <b>i'm a problematic metadata column</b>, or something silly like that. (Also, more realistically, backslashes or ampersands might also cause problems with innerHTML.)