| >>> image |
|  |
| |
| <<< |
| <p><img src="http://foo.com/foo.png" alt="" /></p> |
| >>> alternate text |
|  |
| |
| <<< |
| <p><img src="http://foo.com/foo.png" alt="alternate text" /></p> |
| >>> title |
|  |
| |
| <<< |
| <p><img src="http://foo.com/foo.png" alt="" title="optional title" /></p> |
| >>> invalid alt text |
|  |
| |
| <<< |
| <p><img src="http://foo.com/foo.png" alt="alt" /></p> |
| >>> XSS |
| ) |
| |
| <<< |
| <p><img src="%22onerror=%22alert('XSS')" alt="Uh oh..." /></p> |
| >>> URL-escaping should be left alone inside the destination |
|  |
| <<< |
| <p><img src="https://example/foo%2Fvar" alt="" /></p> |