Your browser is broken if this is a problem. According to the strict DTD, what's in between script tags and event handlers is to be considered CDATA, which is defined as "a sequence of characters from the document character set and may include character entities." ' is a character entity.
IE6 and FF1.5 had no problems handling entities in the event handler when I tested them using the following HTML doc:
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"> <title>test</title> <p><a onclick="alert('FlagNotesTable');">escaped</a> <br><a onclick="alert('FlagNotesTable');">Not escaped</a>
Update: Added first paragraph.
In reply to Re^3: CGI, Javascript and Single Quotes
by ikegami
in thread CGI, Javascript and Single Quotes
by rashley
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |