quoting fixes

- allow bbcode quotes to be nested
- don't allow the '=' to be omitted from quotes
- fix some css that made assumptions about nested quotes
This commit is contained in:
Ben Lubar
2014-05-27 21:46:31 -05:00
parent f6753d3d46
commit 73946e5402
5 changed files with 64 additions and 29 deletions

View File

@ -99,7 +99,7 @@ test("quotes", function() {
"<aside class=\"quote\"><blockquote><p><em>test</em></p></blockquote></aside>",
"it doesn't insert a new line for italics");
format("[quote,script='a'><script>alert('test');//':a][/quote]",
format("[quote=,script='a'><script>alert('test');//':a][/quote]",
"<aside class=\"quote\" data-script=&#x27;a&#x27;&gt;&lt;script&gt;alert(&#x27;test&#x27;);//&#x27;=\"a\"><blockquote></blockquote></aside>",
"It will not create a script tag within an attribute");
});