Source code with ampersands isn't escaped properly in diffs.

Anonymous avatarAnonymous created an issue

In changeset diffs, source lines with HTML entities in them don't display properly. The entities aren't escaped, and so are output verbatim to the browser.

For example, in http://bitbucket.org/ned/coveragepy/changeset/ee491a08fa05/#chg-coverage/htmlfiles/pyfile.html, line 46 contains:

<span class="strut">&nbsp;</span>

but looks like it is:

<span class="strut"> </span>

Tip: Filter by directory path e.g. /media app.js to search for public/media/app.js.
Tip: Use camelCasing e.g. ProjME to search for ProjectModifiedEvent.java.
Tip: Filter by extension type e.g. /repo .js to search for all .js files in the /repo directory.
Tip: Separate your search with spaces e.g. /ssh pom.xml to search for src/ssh/pom.xml.
Tip: Use ↑ and ↓ arrow keys to navigate and return to view the file.
Tip: You can also navigate files with Ctrl+j (next) and Ctrl+k (previous) and view the file with Ctrl+o.
Tip: You can also navigate files with Alt+j (next) and Alt+k (previous) and view the file with Alt+o.