diff --git a/share/static/js/chat.js b/share/static/js/chat.js index daf2e7d1..1f38ffc3 100644 --- a/share/static/js/chat.js +++ b/share/static/js/chat.js @@ -6,11 +6,11 @@ $(function(){ socket.emit('joined', {}); }); socket.on('status', function(data) { - $('#chat').append('
' + data.msg + '
'); + $('#chat').append('' + sanitizeHTML(data.msg) + '
'); $('#chat').scrollTop($('#chat')[0].scrollHeight); }); socket.on('message', function(data) { - $('#chat').append('' + data.msg + '
'); + $('#chat').append('' + sanitizeHTML(data.msg) + '
'); $('#chat').scrollTop($('#chat')[0].scrollHeight); }); $('#new-message').on('keypress', function(e) { @@ -23,8 +23,14 @@ $(function(){ }); }); -function emitMessage(socket) { +var emitMessage = function(socket) { text = $('#new-message').val(); $('#new-message').val(''); socket.emit('text', {msg: text}); } + +var sanitizeHTML = function(str) { + var temp = document.createElement('span'); + temp.textContent = str; + return temp.innerHTML; +};