﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc	focuses
66265	Administration: Avoid $() for selecting with non-literal selectors	jonsurrell		"`$( string )` both selects and parses HTML: a string that starts with `<` creates elements instead of selecting them. When the selector is not a string literal, for example a link `href`, `location.hash`, or a value read from the DOM, the caller decides which of the two happens. Escaping it does not help either: a value concatenated into a selector can change what the selector matches.

Prefer `$( document ).find( selector )`, or a narrower context, which only selects, and escape values interpolated into selectors with `$.escapeSelector()`. r64133 made this change for the contextual help tabs in `common.js`; this ticket covers the remaining instances in admin scripts."	enhancement	new	normal	7.2	Administration		normal		has-patch		javascript
