[ 
https://issues.apache.org/jira/browse/SLING-6490?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15842841#comment-15842841
 ] 

Feike Visser commented on SLING-6490:
-------------------------------------

[~radu.cotescu] thanks for your comment, indeed [~vladb] had a good point on 
sanitising JS/CSS.
Still I don't get it to work. See my example.

> Sightly doesn't render valid style attribute-value
> --------------------------------------------------
>
>                 Key: SLING-6490
>                 URL: https://issues.apache.org/jira/browse/SLING-6490
>             Project: Sling
>          Issue Type: Bug
>          Components: Scripting
>            Reporter: Feike Visser
>            Assignee: Radu Cotescu
>              Labels: Sightly
>
> I have the following piece of Java:
> {code}
> public class Style {
>     public String style = "background-image: url('/path/to/image.jpg');";
> }
> {code}
> I can't get this value printed unless I use @ context = 'unsafe'
> {code}
> <div class="container" data-sly-use.fv="Style" style="${ fv.style @ 
> context='styleToken' }">
>   
> </div>
> {code}



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to