function escape_html(value) { return String(value ?? '').replace(/[&<>"']/g, function(c) { return {'&':'&','<':'<','>':'>','"':'"',"'":'''}[c]; }); } // Text is stored HTML-escaped (see db_statement in dbconn.php), which is right // for anything written into markup but wrong inside a form field: a note saved // as 5" pipe came back as 5" pipe <spare>. Field values // are never parsed as HTML, so decoding them here is safe. function decode_html(value) { if (typeof value !== 'string' || value.indexOf('&') === -1) return value; return value.replace(/&(quot|#0*39|#x0*27|apos|lt|gt|amp);/gi, function (m, name) { name = name.toLowerCase(); if (name === 'quot') return '"'; if (name === 'lt') return '<'; if (name === 'gt') return '>'; if (name === 'amp') return '&'; return "'"; }); } (function ($) { if (!$ || !$.fn || $.fn.val.__decodes_html) return; var original_val = $.fn.val; $.fn.val = function (value) { if (arguments.length && typeof value === 'string') { // Only free-text fields; a