2008
-
03
-
27
escape JavaScript
单引号、双引号、<script></script>标签等等,都可以用Prototype.js的这段代码来escape(sliu真乃JavaScript高人):
- function escapeHTML(str) {
- var div = document.createElement('div' );
- var text = document.createTextNode(str);
- div.appendChild(text);
- return div.innerHTML;
- };