From 76d4beb2cffcabaf0c160a9ad14a6ce51360e2ec Mon Sep 17 00:00:00 2001 From: Trevor Parscal Date: Fri, 1 Oct 2010 18:11:07 +0000 Subject: [PATCH] Improved on r73093 by allowing jQuery to properly escape some HTML attributes. --- resources/mediawiki/mediawiki.js | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/resources/mediawiki/mediawiki.js b/resources/mediawiki/mediawiki.js index fab4a53b51..465e147775 100644 --- a/resources/mediawiki/mediawiki.js +++ b/resources/mediawiki/mediawiki.js @@ -675,12 +675,12 @@ window.mediaWiki = new ( function( $ ) { if ( modules.substr( 0, 7 ) == 'http://' || modules.substr( 0, 8 ) == 'https://' ) { if ( type === 'text/css' ) { setTimeout( function() { - $( 'head' ).append( '' ); + $( 'head' ).append( '' ).attr( 'href', modules ); }, 0 ); return true; } else if ( type === 'text/javascript' || typeof type === 'undefined' ) { setTimeout( function() { - $( 'body' ).append( '' ); + $( 'body' ).append( '' ).attr( 'src', modules ) }, 0 ); return true; } -- 2.20.1