mirror of https://github.com/sveltejs/svelte
fix: escape <textarea value={...}> attribute properly (#8434)
parent
3806977678
commit
5a934e9f43
@ -0,0 +1,4 @@
|
||||
export default {
|
||||
html: '<textarea></textarea>',
|
||||
ssrHtml: '<textarea>test\'"></textarea><script>alert(\'BIM\');</script></textarea>'
|
||||
};
|
@ -0,0 +1 @@
|
||||
<textarea value={`test'"></textarea><script>alert('BIM');</script>`} />
|
Loading…
Reference in new issue