refactor: shared escapeHtml util; escape prop-viewer src/alt

This commit is contained in:
2026-07-20 15:35:57 +01:00
parent 9a5e4c4ce4
commit 5bdeef654e
5 changed files with 35 additions and 10 deletions
+1 -9
View File
@@ -1,14 +1,6 @@
import { generateNpc } from '../npc/generator.js';
import { getGenrePack, listGenrePacks } from '../npc/packs/index.js';
function escapeHtml(s) {
return String(s ?? '')
.replace(/&/g, '&')
.replace(/</g, '&lt;')
.replace(/>/g, '&gt;')
.replace(/"/g, '&quot;')
.replace(/'/g, '&#39;');
}
import { escapeHtml } from '../core/escape-html.js';
export class NpcTray extends HTMLElement {
constructor() {
+3 -1
View File
@@ -1,3 +1,5 @@
import { escapeHtml } from '../core/escape-html.js';
export class PropViewer extends HTMLElement {
constructor() { super(); this._src = ''; this._label = ''; }
connectedCallback() { if (!this.hasAttribute('hidden')) this.setAttribute('hidden', ''); this.render(); }
@@ -14,7 +16,7 @@ export class PropViewer extends HTMLElement {
render() {
this.innerHTML = `
<div class="prop-overlay" data-role="overlay">
<img class="prop-img" data-role="prop-img" src="${this._src}" alt="${this._label}" />
<img class="prop-img" data-role="prop-img" src="${escapeHtml(this._src)}" alt="${escapeHtml(this._label)}" />
</div>`;
this.querySelector('[data-role=overlay]').addEventListener('click', () => this.dismiss());
}
+8
View File
@@ -0,0 +1,8 @@
export function escapeHtml(s) {
return String(s ?? '')
.replace(/&/g, '&amp;')
.replace(/</g, '&lt;')
.replace(/>/g, '&gt;')
.replace(/"/g, '&quot;')
.replace(/'/g, '&#39;');
}