Skip to content

Escape rendered attribute values#104

Open
samalone wants to merge 1 commit intoJohnSundell:masterfrom
samalone:samalone/attribute-escaping
Open

Escape rendered attribute values#104
samalone wants to merge 1 commit intoJohnSundell:masterfrom
samalone:samalone/attribute-escaping

Conversation

@samalone
Copy link
Contributor

This PR adds escaping of single and double quotes in attribute values, ensuring that such characters do not invalidate the HTML.

I encountered this issue when asking Claude Code to perform a security review of my app, which uses JohnSundell/Plot. The changes were generated by Claude Code, but I have reviewed them and believe they are sound.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant