exp/template: escape < and > in JS escaper.
Angle brackets can trigger some browser sniffers, causing some output to be interpreted as HTML. Escaping angle brackets closes that security hole. R=r CC=golang-dev https://golang.org/cl/4714044
Showing
Please register or sign in to comment