【发布时间】:2018-03-01 09:53:14
【问题描述】:
需要修复下面的函数以在listStr 中清理 html,尝试了各种 HTML 转义函数 (listDom.innerHTML = escapeHTML(listStr);) 但我得到的是原始文本而不是元素!
function createList(list) {
let listStr = "";
list.forEach(function (item) {
if (item.click) {
var clean_url = encodeURIComponent(item.href);
clean_url = "";
//console.log(clean_url);
listStr += `<div class='list_item' id="${item.uid}"><a href="javascript:void(0);">${item.label}</a></div>`;
} else {
//'loop', i + ''
listStr += `<div class='list_item' id="${item.uid}" loop="${item.loop}"><a href="${item.href}">${item.label}</a></div>`;
}
});
listStr += '';
let listDom = document.createElement("div");
listDom.setAttribute("id", "list");
listDom.setAttribute("style", "display: none;");
listDom.innerHTML = listStr;
return listDom;
}
【问题讨论】:
标签: javascript html sanitization html-sanitizing