Skip to content

Commit b34961e

Browse files
authored
Merge pull request #68 from d3ward/alert-autofix-4
Potential fix for code scanning alert no. 4: DOM text reinterpreted as HTML
2 parents 6035498 + 0053e7d commit b34961e

1 file changed

Lines changed: 10 additions & 1 deletion

File tree

src/js/components/blacklistManager.js

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,16 @@ export class ItemManager {
1111
if (val.length > 2) {
1212
const div = document.createElement('div')
1313
const id = this.generateID()
14-
div.innerHTML = `<input type="checkbox" name="tbch" id="${id}"><label class="chk" for="${id}">${val}</label>`
14+
const checkbox = document.createElement('input')
15+
checkbox.type = 'checkbox'
16+
checkbox.name = 'tbch'
17+
checkbox.id = id
18+
const label = document.createElement('label')
19+
label.className = 'chk'
20+
label.setAttribute('for', id)
21+
label.textContent = val
22+
div.appendChild(checkbox)
23+
div.appendChild(label)
1524
document.getElementById(this.containerId).prepend(div)
1625
}
1726
}

0 commit comments

Comments
 (0)