Files
codeql/javascript/ql/src/AngularJS/examples/DisablingSce_better.js
2018-08-02 17:53:23 +01:00

7 lines
253 B
JavaScript

angular.module('app', [])
.controller('controller', function($scope, $sce) {
// ...
// GOOD (but should use the templating system instead)
$scope.html = $sce.trustAsHtml('<ul><li>' + item.toString() + '</li></ul>');
});