+ "details": "Given this Hurl file:\n\nregex.hurl:\n\n```\nGET https://foo.com\nHTTP 200\n[Asserts]\njsonpath \"$.body\" matches /<img src=\"\" onerror=\"alert('Hi!')\">/\n```\n\nWhen exported to HTML:\n\n```\n$ hurlfmt --out html regex.hurl\n<pre><code class=\"language-hurl\"><span class=\"hurl-entry\"><span class=\"request\"><span class=\"line\"><span class=\"method\">GET</span> <span class=\"url\">https://foo.com</span></span>\n</span><span class=\"response\"><span class=\"line\"><span class=\"version\">HTTP</span> <span class=\"number\">200</span></span>\n<span class=\"line\"><span class=\"section-header\">[Asserts]</span></span>\n<span class=\"line\"><span class=\"query-type\">jsonpath</span> <span class=\"string\">\"$.body\"</span> <span class=\"predicate-type\">matches</span> <span class=\"regex\">/<img src=\"\" onerror=\"alert('Hi!')\">/</span></span>\n</span></span><span class=\"line\"></span>\n</code></pre>\n```\n\nThe regex literal `/<img src=\"\" onerror=\"alert('Hi!')\">/` is not escaped:\n\n`<span class=\"regex\">/<img src=\"\" onerror=\"alert('Hi!')\">/</span></span>`\n\nWhen opened in a browser, the code is run without user interaction:\n\n",
0 commit comments