In OutputPage::addScriptFile(): escape attributes for HTML. No XSS, just good practice.
authorTim Starling <tstarling@users.mediawiki.org>
Wed, 1 Apr 2009 08:50:57 +0000 (08:50 +0000)
committerTim Starling <tstarling@users.mediawiki.org>
Wed, 1 Apr 2009 08:50:57 +0000 (08:50 +0000)
commit43f0ff44697a6c77800030f53ffeee67b5b71e50
tree48ebe12b03b22a80866e5dd1c4e12c3d9f00bf8e
parentd9ca1dbba57f89f7ce432fdbdc31124fc848cadb
In OutputPage::addScriptFile(): escape attributes for HTML. No XSS, just good practice.
includes/OutputPage.php