From d1193ab44a9ccf410964872d5459f4ffd26bcb8f Mon Sep 17 00:00:00 2001 From: Knut Forkalsrud Date: Sun, 23 Jun 2013 14:32:54 -0700 Subject: [PATCH] no Html escaping in the javascript generated string no html escape in js string --- src/main/webapp/WEB-INF/velocity/dynamic.vm | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/src/main/webapp/WEB-INF/velocity/dynamic.vm b/src/main/webapp/WEB-INF/velocity/dynamic.vm index 9d9f7d6..d5bb686 100644 --- a/src/main/webapp/WEB-INF/velocity/dynamic.vm +++ b/src/main/webapp/WEB-INF/velocity/dynamic.vm @@ -93,7 +93,8 @@ $D(function() { } } - ${D}.getJSON("${entry.name}" + '.json', function(data, textStatus) { + ${D}.getJSON("$esc.url(${entry.name})" + '.json', function(data, textStatus) { +// ${D}.getJSON("${entry.name}" + '.json', function(data, textStatus) { $D("#name").html(data.name);