Skip to main content

f:selectitems item labels are not escaped

1 reply [Last post]
nzinoviev
Offline
Joined: 2008-06-11

I'm using f:selectItems with value pointing to Map, some of the labels contain "<" or ">". I found that values are escaped properly even on default (actually, I do not need that), but labels are not, even if I specify itemLabelEscaped="true".

Here is a test case, add it to some JSF page and then call it with a url like

http://localhost:8080/basic-ezcomp/nav1.jsf?<=h&n=<

here is the resulting html:

<

<

Reply viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.
rlubke
Offline
Joined: 2003-08-21

Thanks for the issue report (1018). We've applied the fix and it should be available in tonight's nightly build.