ANadig / YellowFruit

QB Stats App
15 stars 7 forks source link

Tooltip can have JavaScript #34

Closed alopezlago closed 2 years ago

alopezlago commented 2 years ago

https://github.com/ANadig/YellowFruit/blob/67b9d604668be17755e02014ca42e57007fe5424/process/ts/TeamListEntry.tsx#L97

material-css doesn't encode text in tooltips, so hovering over the trash icon in the team entry view can execute JavaScript.

ANadig commented 2 years ago

Fixed in 3.0.0