/** * ajax_core.js — helpers every page needs, including the sign-in pages: * HTML escaping, form-data collection, the ajax_request() wrapper, the * page-wide form-submit guard and live required-field validation. * * Loaded by include_header.php (before custom.js) and by the minimal * login/include_login_header.php, so the sign-in pages no longer download * custom.js with every feature's API URLs. */ function escape_html(value) { return String(value ?? '').replace(/[&<>"']/g, function(c) { return {'&':'&','<':'<','>':'>','"':'"',"'":'''}[c]; }); } // Text is stored HTML-escaped (see db_statement in dbconn.php), which is right // for anything written into markup but wrong inside a form field: a note saved // as 5" pipe came back as 5" pipe <spare>. Field values // are never parsed as HTML, so decoding them here is safe. function decode_html(value) { if (typeof value !== 'string' || value.indexOf('&') === -1) return value; return value.replace(/&(quot|#0*39|#x0*27|apos|lt|gt|amp);/gi, function (m, name) { name = name.toLowerCase(); if (name === 'quot') return '"'; if (name === 'lt') return '<'; if (name === 'gt') return '>'; if (name === 'amp') return '&'; return "'"; }); } (function ($) { if (!$ || !$.fn || $.fn.val.__decodes_html) return; var original_val = $.fn.val; $.fn.val = function (value) { if (arguments.length && typeof value === 'string') { // Only free-text fields; a