diff options
| author | Eskil Abrahamsen Blomfeldt <eskil.abrahamsen-blomfeldt@qt.io> | 2025-11-13 09:44:08 +0100 |
|---|---|---|
| committer | Eskil Abrahamsen Blomfeldt <eskil.abrahamsen-blomfeldt@qt.io> | 2025-11-21 07:38:13 +0100 |
| commit | a6f73cd795c1fc497d20aec81cfcad7be8878297 (patch) | |
| tree | b747d3027434017f6e2b06865e33981c1494beb2 /src/qml/jsapi/qjsengine.cpp | |
| parent | 541e7c1115512fe54aa3a5c5c382ae9647848fa7 (diff) | |
doc: Document caveats of setting user input on Text component
The HTML subset in Qt was never intended to be end user facing
and is very specifically modelled to Qt's needs.
Without precaution, an application can easily end up setting a
user provided string as content on the Text component. This can
cause both unexpected results for the end users (if they expect
a compliant HTML engine) and arbitrary image loading/allocation.
Since the default text format of Text is AutoText, we make sure
to document that user provided data should not be set directly as
content on the label unless the PlainText format is explicitly
selected.
Pick-to: 6.5 6.8 6.10
Change-Id: I4383389640ff140da1ccbdf58e198e2868ad9774
Reviewed-by: Volker Hilsheimer <volker.hilsheimer@qt.io>
Reviewed-by: Eirik Aavitsland <eirik.aavitsland@qt.io>
Diffstat (limited to 'src/qml/jsapi/qjsengine.cpp')
0 files changed, 0 insertions, 0 deletions
