diff --git a/markdown.js b/markdown.js index 6c92953..78ff977 100644 --- a/markdown.js +++ b/markdown.js @@ -361,12 +361,12 @@ function embed(links) { embeddedElement.classList.add("scratch-embed"); const request = new XMLHttpRequest(); - request.open('GET', `https://trampoline.turbowarp.org/api/projects/${trackId}`); + request.open('GET', `https://trampoline.turbowarp.org/api/projects/${escapeHtml(trackId)}`); request.onload = () => { const data = JSON.parse(request.responseText); embeddedElement.innerHTML = ` - -
+ + ` } request.send(); @@ -384,12 +384,12 @@ function embed(links) { embeddedElement.classList.add("scratch-embed"); const request = new XMLHttpRequest(); - request.open('GET', `https://trampoline.turbowarp.org/api/projects/${trackId}`); + request.open('GET', `https://trampoline.turbowarp.org/api/projects/${escapeHtml(trackId)}`); request.onload = () => { const data = JSON.parse(request.responseText); embeddedElement.innerHTML = ` - - + + ` } request.send(); @@ -417,12 +417,12 @@ function embed(links) { post = `User submitted image`; } embeddedElement.innerHTML = ` - +