clemos / try-haxe

A small webapp that allows to test Haxe online
https://try.haxe.org
MIT License
126 stars 41 forks source link

HTML strings not escaped #110

Closed laurence-myers closed 8 years ago

laurence-myers commented 8 years ago

I stumbled across this snippet:

http://try.haxe.org/embed/730b9

Looks like this snippet has a string containing HTML; the HTML is getting rendered, instead of appearing as basic text.

Similar to #81.

clemos commented 8 years ago

indeed, duplicate of #81, but thanks for the heads up :)