File tree Expand file tree Collapse file tree 1 file changed +5
-4
lines changed Expand file tree Collapse file tree 1 file changed +5
-4
lines changed Original file line number Diff line number Diff line change 11import { emojiKeys , emojiHTML , emojiString } from './emoji.js' ;
22import { uniq } from '../utils.js' ;
3+ import { htmlEscape } from 'escape-goat' ;
34
45function makeCollections ( { mentions, emoji} ) {
56 const collections = [ ] ;
@@ -24,7 +25,7 @@ function makeCollections({mentions, emoji}) {
2425 return emojiString ( item . original ) ;
2526 } ,
2627 menuItemTemplate : ( item ) => {
27- return `<div class="tribute-item">${ emojiHTML ( item . original ) } <span>${ item . original } </span></div>` ;
28+ return `<div class="tribute-item">${ emojiHTML ( item . original ) } <span>${ htmlEscape ( item . original ) } </span></div>` ;
2829 }
2930 } ) ;
3031 }
@@ -36,9 +37,9 @@ function makeCollections({mentions, emoji}) {
3637 menuItemTemplate : ( item ) => {
3738 return `
3839 <div class="tribute-item">
39- <img src="${ item . original . avatar } "/>
40- <span class="name">${ item . original . name } </span>
41- ${ item . original . fullname && item . original . fullname !== '' ? `<span class="fullname">${ item . original . fullname } </span>` : '' }
40+ <img src="${ htmlEscape ( item . original . avatar ) } "/>
41+ <span class="name">${ htmlEscape ( item . original . name ) } </span>
42+ ${ item . original . fullname && item . original . fullname !== '' ? `<span class="fullname">${ htmlEscape ( item . original . fullname ) } </span>` : '' }
4243 </div>
4344 ` ;
4445 }
You can’t perform that action at this time.
0 commit comments