Hacker News new | ask | show | jobs
by sirn 5184 days ago
Nice idea, but seems to lack of any input escaping.

    => Humanize.truncatechars("<script>alert('yo');<\/script>", 30)
       "<script>alert('yo');</script>"

    => Humanize.linebreaks("<script>alert('yo');<\/script>")
       "<p><script>alert('yo');</script></p>"
Bug filed.
1 comments

Thanks. I am on it.