1/** 2 * Backport of security fixes from: 3 * https://github.com/jquery/jquery-ui/pull/1953 4 * https://github.com/jquery/jquery-ui/pull/1954 5 */ 6 7(function ($, Drupal) { 8 9 // No backport is needed if we're already on jQuery UI 1.13 or higher. 10 var versionParts = $.ui.datepicker.version.split('.'); 11 var majorVersion = parseInt(versionParts[0]); 12 var minorVersion = parseInt(versionParts[1]); 13 if ( (majorVersion > 1) || (majorVersion === 1 && minorVersion >= 13) ) { 14 return; 15 } 16 17 var fnOriginalGet = $.datepicker._get; 18 $.extend($.datepicker, { 19 20 _get: function( inst, name ) { 21 var val = fnOriginalGet.call(this, inst, name); 22 23 // @see https://github.com/jquery/jquery-ui/pull/1954 24 if (name === 'altField') { 25 val = $(document).find(val); 26 } 27 // @see https://github.com/jquery/jquery-ui/pull/1953 28 else if ($.inArray(name, ['appendText', 'buttonText', 'prevText', 'currentText', 'nextText', 'closeText']) !== -1) { 29 val = Drupal.checkPlain(val); 30 } 31 32 return val; 33 } 34 35 }) 36})(jQuery, Drupal);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.