biocore/empress

When setting text in the DOM, use textContent instead of innerHTML

開放

#216 建立於 2020年6月26日

 (0 則留言) (1 個反應) (0 位負責人)JavaScript (32 個分叉)auto 404
good first issuerefactoring

倉庫指標

星標
 (56 顆星)
PR 合併指標
 (30 天內沒有已合併 PR)

描述

See the MDN docs on some of the downsides of setting things with innerHTML here.

This shouldn't be a huge problem since Empress visualizations are (as of writing) inherently client-side applications, but there's the potential for users to break things if their data includes bizarre names -- for example, a metadata column is named <b>i'm a problematic metadata column</b>, or something silly like that. (Also, more realistically, backslashes or ampersands might also cause problems with innerHTML.)

貢獻者指南