Make WordPress Core


Ignore:
Timestamp:
09/04/2019 05:11:22 PM (5 years ago)
Author:
whyisjake
Message:

Update wp.a11y.speak() to sanitize HTML before display.

Props iandunn, adamsilverstein, sstoqnov, peterwilsoncc

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/src/js/_enqueues/wp/customize/nav-menus.js

    r45869 r45979  
    34573457    function displayNavMenuName( name ) {
    34583458        name = name || '';
    3459         name = $( '<div>' ).text( name ).html(); // Emulate esc_html() which is used in wp-admin/nav-menus.php.
     3459        name = wp.sanitize.stripTagsAndEncodeText( name ); // Remove any potential tags from name.
    34603460        name = $.trim( name );
    34613461        return name || api.Menus.data.l10n.unnamed;
Note: See TracChangeset for help on using the changeset viewer.