http://codereview.appspot.com/5648043/diff/3001/src/com/google/caja/ses/compileExprLater.js
File src/com/google/caja/ses/compileExprLater.js (right):

http://codereview.appspot.com/5648043/diff/3001/src/com/google/caja/ses/compileExprLater.js#newcode105
src/com/google/caja/ses/compileExprLater.js:105: scriptSrc = '/* from '
+ opt_sourceUrl + ' */ ' + scriptSrc;
Note to self.  This isn't sufficient to escape opt_sourceUrl.

http://codereview.appspot.com/5648043/

Reply via email to