- 
  Notifications
 You must be signed in to change notification settings 
- Fork 121
Closed
@meeque 
Description
Currently the Encode.forHtmlAttribute JavaDocs contain this JSP example:
<div><%=Encode.forHtmlAttribute(unsafeData)%></div>
I guess this may be secure, but imho it does not reflect the intention of this method. How about using an example that involves html attributes? Maybe something like this:
<div title="<%=Encode.forHtmlAttribute(unsafeData)%>">...</div>
<div title='<%=Encode.forHtmlAttribute(unsafeData)%>'>...</div>
Imho the JavaDocs should also mention that the caller of this method must add quotes around the outputs of this method.
If you think any of this is helpful, I can prepare a PR.
Metadata
Metadata
Assignees
Labels
No labels