From 11e042f6c12bc52bac1a6ec03a2be6f19b592890 Mon Sep 17 00:00:00 2001 From: Martin Probst Date: Sat, 3 May 2014 12:58:25 +0200 Subject: [PATCH] Avoid raw mode parsing so that raw mode tags like ">`, - "

<script>alert(&quot;XSS&quot;)</script>">

\n", + "

<script>alert("XSS")</script>">

\n", "", "

\n", @@ -182,18 +182,14 @@ func TestRawHtmlTag(t *testing.T) { ``, "

<script/SRC="http://ha.ckers.org/xss.js"></script>

\n", - // HTML5 interprets the `, - "

<<script>alert(&quot;XSS&quot;);//&lt;</script>

\n", + "

<<script>alert("XSS");//<</script>

\n", - // HTML5 parses the

within an unclosed