html escape assignment titles in gradebook importer, refs #3888

Change-Id: Ia13827f3ef8c28c18c74b57093a5ed219e67a88e
Reviewed-on: https://gerrit.instructure.com/2408
Reviewed-by: Bracken Mosbacker <bracken@instructure.com>
Tested-by: Hudson <hudson@instructure.com>
This commit is contained in:
Zach Wily 2011-02-23 12:57:08 -07:00
parent 8868162722
commit 39db2a2199
1 changed files with 2 additions and 2 deletions

View File

@ -45,7 +45,7 @@ var GradebookUploader = {
$.each(mergedGradebook.assignments, function(){
gridData.columns.push({
id: this.id,
name: this.title,
name: $.htmlEscape(this.title),
field: this.id,
width:200,
editor: NullGradeEditor,
@ -79,7 +79,7 @@ var GradebookUploader = {
else {
col = {
id: assignment.id,
name: assignment.title,
name: $.htmlEscape(assignment.title),
field: assignment.id,
formatter: simpleGradeCellFormatter,
cssClass: "active new"