mirror of
https://github.com/alexhopeoconnor/WiFiManager.git
synced 2026-10-04 02:48:13 +10:00
Escape single quotes in htmlEntities() (#1413)
This should allow SSIDs that contain single quotes to populate data-ssid correctly. Without this patch, clicking on an SSID containing a single quote will either: * Not use the whole SSID, in cases where there's text before the quote: `foo'bar` will appear in the SSID box as just `foo` * Fall back to innerText, in cases where the quote is the first character in the SSID: `'); DROP TABLE WIFI; --` will appear in the SSID box as a version that has spaces converted to non-breaking spaces, causing the connection to eventually fail with WL_NO_SSID_AVAIL.
This commit is contained in:
@@ -3363,6 +3363,7 @@ String WiFiManager::htmlEntities(String str, bool whitespace) {
|
||||
str.replace("&","&");
|
||||
str.replace("<","<");
|
||||
str.replace(">",">");
|
||||
str.replace("'","'");
|
||||
if(whitespace) str.replace(" "," ");
|
||||
// str.replace("-","–");
|
||||
// str.replace("\"",""");
|
||||
|
||||
Reference in New Issue
Block a user