Use appendChild instead of innerHTML for security reason Change-Id: I2d889d4356e3b1e9a72fd4c165cc47a1789b2a64
diff --git a/gr-resemble-diff-mode/gr-resemble-diff-mode.js b/gr-resemble-diff-mode/gr-resemble-diff-mode.js index c7b7cba..cd0711a 100644 --- a/gr-resemble-diff-mode/gr-resemble-diff-mode.js +++ b/gr-resemble-diff-mode/gr-resemble-diff-mode.js
@@ -188,7 +188,7 @@ _handleFullScreen() { const w = window.open('about:blank', '_blank'); - w.document.body.innerHTML = this.$.imageDiff.outerHTML; + w.document.body.appendChild(this.$.imageDiff.cloneNode(true)); } }