From 1ecf3db5fcd48fe9b6c9140c7513080fbb28aa1e Mon Sep 17 00:00:00 2001 From: jakubvrana Date: Tue, 1 Mar 2016 18:16:07 -0800 Subject: [PATCH] Use goog.dom.safeHtmlToNode instead of deprecated htmlToDocumentFragment. goog.dom.htmlToDocumentFragment is going to be removed in [] It is removed because its usage can cause XSS. More information: [] Tested: TAP --sample for global presubmit queue [] ------------- Created by MOE: https://github.com/google/moe MOE_MIGRATED_REVID=116081948 --- javatests/com/google/domain/registry/ui/js/testing.js | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/javatests/com/google/domain/registry/ui/js/testing.js b/javatests/com/google/domain/registry/ui/js/testing.js index 18e9f35fb..bba01e30c 100644 --- a/javatests/com/google/domain/registry/ui/js/testing.js +++ b/javatests/com/google/domain/registry/ui/js/testing.js @@ -21,6 +21,7 @@ goog.require('goog.dom.classlist'); goog.require('goog.dom.xml'); goog.require('goog.events.EventType'); goog.require('goog.format.JsonPrettyPrinter'); +goog.require('goog.html.legacyconversions'); goog.require('goog.json'); goog.require('goog.testing.asserts'); goog.require('goog.testing.events'); @@ -34,7 +35,8 @@ goog.require('goog.testing.net.XhrIo'); */ registry.testing.addToDocument = function(html) { goog.global.document.body.appendChild( - goog.dom.htmlToDocumentFragment(html)); + goog.dom.safeHtmlToNode( + goog.html.legacyconversions.safeHtmlFromString(html))); };