What parts of JavaScript code do I have to escape inside a script element in a HTML page? Is <>& enough or too much?
script
<>&
[EDI
Generally, the only thing I escape is the / in closing tags. Thus:
/
var msg = "Do you really<\/em> think so, Miss Worthington?<\/p>";
Do you really<\/em> think so, Miss Worthington?<\/p>";
For the rest, I rely on commenting out the entire thing:
The comment takes care of the HTML opening tags.