[web] scripts/translations: sanitize: double down on angular xss GitOrigin-RevId: d08deab392942e593e920e648118f0e196af1740
@@ -25,6 +25,9 @@ function sanitize(input) {
a: ['href', 'class'],
},
textFilter(text) {
+ // Block Angular XSS
+ if (text === '{') return '{'
+ if (text === '}') return '}'
return text
.replace(/\{\{/, '{{')
.replace(/\}\}/, '}}')