Lazyweb: If I'm inserting some JSON into a <script> via a template, is there anything I need to escape other than </script>?
-
-
Replying to @jaffathecake
https://mathiasbynens.be/notes/json-dom-csp … details the escaping requirements for various contexts. In <script>, escape `<!--` too.
1 reply 0 retweets 8 likes -
Replying to @mathias
this is great, apologies for not reading it properly earlier
1 reply 0 retweets 1 like
Replying to @jaffathecake
No worries — the CSP mention might’ve made it seem like it was about something else. Glad you thought it was useful after all!
10:32 PM - 14 Oct 2016
0 replies
0 retweets
2 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
JavaScript, HTML, CSS, HTTP, performance, security, Bash, Unicode, i18n, macOS.