html escape <%= and don't escape <%-

This commit is contained in:
leaf corcoran
2013-10-23 23:53:22 -07:00
parent 5cf2890dba
commit 79ad17f9f1
2 changed files with 29 additions and 20 deletions

View File

@@ -22,10 +22,14 @@ describe "elua", ->
}
{
"y%>u"
"y%&gt;u"
[[<%= "y%>u" %>]]
}
{
"y%>u"
[[<%- "y%>u" %>]]
}
{
[[
@@ -35,29 +39,19 @@ This is my message to 4
hello 1
hello 2
hello 3
hello 4
hello 5
hello 6
hello 7
hello 8
hello 9
hello 10
message: yeah
This is my message to oh yeah %>"]]
This is my message to oh yeah %&gt;&quot;]]
[[
This is my message to <%= "you" %>
This is my message to <%= 4 %>
@@ -66,7 +60,7 @@ This is my message to <%= 4 %>
<% end %>
<% for i=1,10 do%>
hello <%= i %>
hello <%= i -%>
<% end %>
message: <%= visitor %>