Closed stephendonner closed 1 year ago
I suspect the original point of escaping was to avoid XSS/HTML injection in feed titles so please make sure the fix for this has sec review
I think this is related to https://github.com/brave/news-aggregator/issues/44
Note: I don't think we need to worry about XSS/HTML injection because the places this is used are either:
This seems to have been fixed a while ago!
Description
Need to unescape special characters in feed titles
Steps to Reproduce
1.47.14
brave://flags
brave://flags/#brave-news-v2
toEnabled
Relaunch
Customize
Brave News
Turn on Brave News
food
in theDiscover
search textfieldFood & Wine Magazine
entryActual result:
Expected result:
Food & Wine Magazine
Reproduces how often:
100%
Brave version (brave://version info)
Version/Channel Information:
Other Additional Information:
Miscellaneous Information:
cc @mattmcalister @rebron @fallaciousreasoning @petemill @brave/qa-team