call escape markup on results
This commit is contained in:
parent
c90bfc3e22
commit
e78dc69a6b
@ -698,7 +698,7 @@ the specific language governing permissions and limitations under the Apache Lic
|
|||||||
label=$(document.createElement("div"));
|
label=$(document.createElement("div"));
|
||||||
label.addClass("select2-result-label");
|
label.addClass("select2-result-label");
|
||||||
|
|
||||||
formatted=opts.formatResult(result, label, query);
|
formatted=opts.escapeMarkup(opts.formatResult(result, label, query));
|
||||||
if (formatted!==undefined) {
|
if (formatted!==undefined) {
|
||||||
label.html(formatted);
|
label.html(formatted);
|
||||||
}
|
}
|
||||||
|
Loading…
Reference in New Issue
Block a user