cubicweb #2035033 href containing "javascript: " doesn't escape %\d\d [validation pending]
url quote sequence /%\d\d/``are interpreted in ``href="javascript: " before being sent to the js engine. This can lead to bug when url of js call contains such sequence. | |
priority | normal |
---|---|
type | bug |
done in | 3.14.0 |
load | 0.400 |
load left | 0.000 |
closed by | #9ef285eb20f4 [utils] add a ``js_href`` function to generated proper javascript href |