Commit ce405e71 authored by Everett Sochowski's avatar Everett Sochowski

Use html escaping in the underscore templates

parent 2b46d3e4
......@@ -33,16 +33,16 @@
<script type="text/template" id="item-template">
<div class="view">
<input class="toggle" type="checkbox" <%= done ? 'checked="checked"' : '' %> />
<label><%= title %></label>
<input class="toggle" type="checkbox" <%- done ? 'checked="checked"' : '' %> />
<label><%- title %></label>
<button class="destroy"></button>
</div>
<input class="edit" type="text" value="<%= title %>" />
<input class="edit" type="text" value="<%- title %>" />
</script>
<script type="text/template" id="stats-template">
<footer id="footer">
<span id="todo-count"><strong><%= remaining %></strong> <%= remaining == 1 ? 'item' : 'items' %> left</span>
<span id="todo-count"><strong><%- remaining %></strong> <%- remaining == 1 ? 'item' : 'items' %> left</span>
<ul id="filters">
<li>
<a class="selected" href="#/">All</a>
......@@ -55,7 +55,7 @@
</li>
</ul>
<% if (done) { %>
<button id="clear-completed">Clear <%= done %> completed <%= done == 1 ? 'item' : 'items' %></button>
<button id="clear-completed">Clear <%- done %> completed <%- done == 1 ? 'item' : 'items' %></button>
<% } %>
</footer>
</script>
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment