if ( oObj.waiting_here ) {
data += __("Item is <strong>waiting here</strong>");
if (oObj.desk_name) {
- data += ", " + __("at %s").format(oObj.desk_name);
+ data += ", " + __("at %s").format(oObj.desk_name.escapeHtml());
}
} else {
data += __("Item is <strong>waiting</strong>");
data += " " + __("at %s").format(oObj.waiting_at);
if (oObj.desk_name) {
- data += ", " + __("at %s").format(oObj.desk_name);
+ data += ", " + __("at %s").format(oObj.desk_name.escapeHtml());
}
}
}
});
});
-
});