Browse Source

Merge pull request #174461 in DEC/fineui from master to feature/x

* commit 'b75c5ab27215fceb55a15491028151321ef0177a':
  auto upgrade version to 2.0.20220916093936
  REPORT-80245 fix: jquery低版本漏洞
master
superman 2 years ago
parent
commit
0d02e31221
  1. 2
      package.json
  2. 34
      src/core/platform/web/jquery/_jquery.js

2
package.json

@ -1,6 +1,6 @@
{
"name": "fineui",
"version": "2.0.20220914200441",
"version": "2.0.20220916093936",
"description": "fineui",
"main": "dist/fineui_without_conflict.min.js",
"types": "dist/lib/index.d.ts",

34
src/core/platform/web/jquery/_jquery.js vendored

@ -10552,7 +10552,16 @@
}
});
// Support: Safari 8 only
// In Safari 8 documents created via document.implementation.createHTMLDocument
// collapse sibling forms: the second one becomes a child of the first one.
// Because of that, this security measure has to be disabled in Safari 8.
// https://bugs.webkit.org/show_bug.cgi?id=137337
support.createHTMLDocument = (function () {
var body = document.implementation.createHTMLDocument("").body;
body.innerHTML = "<form></form><form></form>";
return body.childNodes.length === 2;
})();
// data: string of html
@ -10567,9 +10576,28 @@
keepScripts = context;
context = false;
}
context = context || document;
var parsed = rsingleTag.exec( data ),
var base, parsed, scripts;
if (!context) {
// Stop scripts or inline event handlers from being executed immediately
// by using document.implementation
if (support.createHTMLDocument) {
context = document.implementation.createHTMLDocument("");
// Set the base href for the created document
// so any parsed elements with URLs
// are based on the document's URL (gh-2965)
base = context.createElement("base");
base.href = document.location.href;
context.head.appendChild(base);
} else {
context = document;
}
}
parsed = rsingleTag.exec(data);
scripts = !keepScripts && [];
// Single tag

Loading…
Cancel
Save