I think it is now somewhat disabled. you just need to refresh the page.
msg.text =
msg.text.replace('>','')
.replace('<','')
.replace(';','')
.replace('/','')
.replace('\\','')
.replace('\'','')
.replace('\"','')
.replace(':"','')
.replace('!important','');
I will think of a more clever solution next week :) var entityMap = {
"&": "&",
"<": "<",
">": ">",
'"': '"',
"'": ''',
"/": '/'
};
function escapeHtml(string) {
return String(string).replace(/[&<>"'\/]/g, function (s) {
return entityMap[s];
});
}
also document.createTextNode will tell the browser not to render the children as html, whereas appending a dom element and innerHTML will.[1] I'm just assuming that behavior is correct in all browsers though.[0]https://github.com/janl/mustache.js/blob/master/mustache.js#...
div.textContent = msg;
msg.text = div.innerHTML;
This should remove all HTML/CSS/Script.