* Convert a value into the proper css writable value. The style name `name` * should be logical (no hyphens), as specified * in `CSSProperty.isUnitlessNumber`. * * @param {string} name CSS property name such as `topMargin`. * @param {*} value CSS property value such as `10px`. * @return {strin
(name, value, isCustomProperty)
| 14176 | * @return {string} Normalized style value with dimensions applied. |
| 14177 | */ |
| 14178 | function dangerousStyleValue(name, value, isCustomProperty) { |
| 14179 | // Note that we've removed escapeTextForBrowser() calls here since the |
| 14180 | // whole string will be escaped when the attribute is injected into |
| 14181 | // the markup. If you provide unsafe user data here they can inject |
| 14182 | // arbitrary CSS which may be problematic (I couldn't repro this): |
| 14183 | // https://www.owasp.org/index.php/XSS_Filter_Evasion_Cheat_Sheet |
| 14184 | // http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/ |
| 14185 | // This is not an XSS hole but instead a potential CSS injection issue |
| 14186 | // which has lead to a greater discussion about how we're going to |
| 14187 | // trust URLs moving forward. See #2115901 |
| 14188 | |
| 14189 | var isEmpty = value == null || typeof value === 'boolean' || value === ''; |
| 14190 | if (isEmpty) { |
| 14191 | return ''; |
| 14192 | } |
| 14193 | |
| 14194 | if (!isCustomProperty && typeof value === 'number' && value !== 0 && !(isUnitlessNumber.hasOwnProperty(name) && isUnitlessNumber[name])) { |
| 14195 | return value + 'px'; // Presumes implicit 'px' suffix for unitless numbers |
| 14196 | } |
| 14197 | |
| 14198 | return ('' + value).trim(); |
| 14199 | } |
| 14200 | |
| 14201 | var warnValidStyle = emptyFunction; |
| 14202 |
no outgoing calls
no test coverage detected