From fef9ec476cacd5f52ecc43dc0d35360da0a8b5b0 Mon Sep 17 00:00:00 2001 From: Roman Hotsiy Date: Wed, 15 Nov 2017 09:40:55 +0200 Subject: [PATCH 1/2] fix: html characters not escaped in code blocks (fixes #378) if lang is not specified --- lib/utils/md-renderer.ts | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/lib/utils/md-renderer.ts b/lib/utils/md-renderer.ts index 9e2c890c..1fe16d1a 100644 --- a/lib/utils/md-renderer.ts +++ b/lib/utils/md-renderer.ts @@ -5,6 +5,13 @@ import * as slugify from 'slugify'; import * as Remarkable from 'remarkable'; import { StringMap } from './'; +function HTMLescape(html: string): string { + return document.createElement('div') + .appendChild(document.createTextNode(html)) + .parentElement + .innerHTML; +} + declare var Prism: any; const md = new Remarkable({ html: true, @@ -15,7 +22,7 @@ const md = new Remarkable({ if (lang === 'json') lang = 'js'; let grammar = Prism.languages[lang]; // fallback to click - if (!grammar) return str; + if (!grammar) return HTMLescape(str); return Prism.highlight(str, grammar); } }); From 49695c62c9bfe1e35f6e5a45a9f8b39f1da71b8e Mon Sep 17 00:00:00 2001 From: Roman Hotsiy Date: Thu, 16 Nov 2017 15:18:55 +0200 Subject: [PATCH 2/2] chore: release v1.19.3 --- CHANGELOG.md | 18 ++++++++++++++++++ package.json | 2 +- 2 files changed, 19 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 4da43598..b8bb699e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,21 @@ + +## [1.19.3](https://github.com/Rebilly/ReDoc/compare/v1.19.2...v1.19.3) (2017-11-16) + + +### Bug Fixes + +* html characters not escaped in code blocks (fixes [#378](https://github.com/Rebilly/ReDoc/issues/378)) ([fef9ec4](https://github.com/Rebilly/ReDoc/commit/fef9ec4)) + + + +## [1.19.2](https://github.com/Rebilly/ReDoc/compare/v1.19.1...v1.19.2) (2017-11-10) + + +### Bug Fixes + +* response samples doesn't show only text/plain (fixes [#371](https://github.com/Rebilly/ReDoc/issues/371)) ([00aea06](https://github.com/Rebilly/ReDoc/commit/00aea06)) + + # [1.19.1](https://github.com/Rebilly/ReDoc/compare/v1.19.0...v1.19.1) (2017-10-02) diff --git a/package.json b/package.json index 969dff06..f2d5a7ec 100644 --- a/package.json +++ b/package.json @@ -1,7 +1,7 @@ { "name": "redoc", "description": "Swagger-generated API Reference Documentation", - "version": "1.19.2", + "version": "1.19.3", "repository": { "type": "git", "url": "git://github.com/Rebilly/ReDoc"