From shavivi at redhat.com Tue Jul 1 03:38:00 2014 Content-Type: multipart/mixed; boundary="===============1739790927581430262==" MIME-Version: 1.0 From: shavivi at redhat.com To: engine-commits at ovirt.org Subject: Change in ovirt-engine[master]: ui: remove Escape characters for TextBoxLabel Date: Tue, 01 Jul 2014 03:37:59 -0400 Message-ID: <201407010737.s617bxvo014780@gerrit.ovirt.org> In-Reply-To: gerrit.1403793731562.I2e303decb9395fcf193e874b4ae55ab076ec0bba@gerrit.ovirt.org --===============1739790927581430262== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Shahar Havivi has submitted this change and it was merged. Change subject: ui: remove Escape characters for TextBoxLabel ...................................................................... ui: remove Escape characters for TextBoxLabel The reason that we use: SafeHtmlUtils.htmlEscape(renderedText); is to prevent javascript code injection such as