HTML-escape the five significant characters so no interpolated string can inject markup.
(s: &str)
| 493 | /// HTML-escape the five significant characters so no interpolated string can |
| 494 | /// inject markup. |
| 495 | fn html_escape(s: &str) -> String { |
| 496 | let mut out = String::with_capacity(s.len()); |
| 497 | for ch in s.chars() { |
| 498 | match ch { |
| 499 | '&' => out.push_str("&"), |
| 500 | '<' => out.push_str("<"), |
| 501 | '>' => out.push_str(">"), |
| 502 | '"' => out.push_str("""), |
| 503 | '\'' => out.push_str("'"), |
| 504 | _ => out.push(ch), |
| 505 | } |
| 506 | } |
| 507 | out |
| 508 | } |
| 509 | |
| 510 | /// Escape a JSON payload for safe embedding inside a `<script>` element: the |
| 511 | /// `<`, `>`, and `&` bytes are rewritten to their `\u00XX` JSON escapes so the |
no test coverage detected