biocore/empress

When setting text in the DOM, use textContent instead of innerHTML

开放

#216 创建于 2020年6月26日

 (0 条评论) (1 个反应) (0 位负责人)JavaScript (32 个派生)auto 404
good first issuerefactoring

仓库指标

星标
 (56 个星标)
PR 合并指标
 (PR 指标待抓取)

描述

See the MDN docs on some of the downsides of setting things with innerHTML here.

This shouldn't be a huge problem since Empress visualizations are (as of writing) inherently client-side applications, but there's the potential for users to break things if their data includes bizarre names -- for example, a metadata column is named <b>i'm a problematic metadata column</b>, or something silly like that. (Also, more realistically, backslashes or ampersands might also cause problems with innerHTML.)

贡献者指南