Last modified: 2014-10-30 01:42:10 UTC
There's no simple way to add HTML-escaped text to a Element. OoUiTag::appendContent() doesn't escape strings. I say we should add a appendText() method and use it where applicable.
We currently have some bugs where JS and PHP escape things differently because of this.
Change 169106 had a related patch set uploaded by Bartosz Dziewoński: OoUiTag: HTML-escape everything by default https://gerrit.wikimedia.org/r/169106
Change 169106 merged by jenkins-bot: OoUiTag: HTML-escape everything by default https://gerrit.wikimedia.org/r/169106