Skip to content

Conversation

kevincarrogan
Copy link

When there are options with '& amp; p' in their text when searching for 'p' the 'p' in & amp; will be wrapped in em tags instead of the actual 'p' that was found in the search.

See http://jsfiddle.net/hmwjC/ for an example.

This should also fix any other values with character entities.

@ghost
Copy link

ghost commented Feb 3, 2013

+1

1 similar comment
@lephyrius
Copy link

+1

@pfiller
Copy link
Contributor

pfiller commented Apr 18, 2013

Thanks @kevindmorgan

option.html was used to solve an xss issue that was present in Chosen. I've created a new issue (#1150) to discuss a solution that searches text, but in a safe way. Please feel free to contribute there if you have ideas.

Closing until a safe solution is clear.

@pfiller pfiller closed this Apr 18, 2013
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants