FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Why "encodeForHTMLAttribute" encodes '@' too? · Issue #4 · ESAPI/node-esapi · GitHub

Repository navigation

Why "encodeForHTMLAttribute" encodes '@' too? #4

Description

The function encodeForHTMLAttribute encodes the symbol '@' too. However, if we have such an element:

<input id="email" autocomplete="off" type="email" placeholder="youremail@company.com" class="form-control" name="email" value="user@example.com" maxlength="100" autofocus="">

then encodeForHTMLAttribute encodes 'user@example.com' it to user&#x40;example.com.
What is the right way to encode this value so it looks like user@example.com?

Thanks,

Activity

  1. changed the title [-]Why does encodeForHTMLAttribute encodes '@' too?[/-] [+]Why does encodeForHTMLAttribute encode '@' too?[/+] on Aug 4, 2017
  2. changed the title [-]Why does encodeForHTMLAttribute encode '@' too?[/-] [+]Why "encodeForHTMLAttribute" encodes '@' too?[/+] on Aug 4, 2017
  3. xeno6696 commented on Aug 6, 2022

    Off the cuff I’m not sure as the At symbol isn’t reserved.

    I don’t manage the node version of this, but it sounds like it could be a bug. Is the @ symbol used in javascript backends? I’m not familiar with node.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions


      Back | FazBrowse Home | New Git URL