Skip to content

Fix unclosed script tag for injected JavaScript in Swagger UI - #286

Merged
dzikoysk merged 1 commit into
javalin:mainfrom
anibalxyz:fix/swagger-injected-script-closing-tag
Sep 21, 2026
Merged

dzikoysk merged 1 commit into
javalin:mainfrom
anibalxyz:fix/swagger-injected-script-closing-tag

Conversation

@anibalxyz

Copy link
Copy Markdown
Contributor

I tried injecting a custom JS file with injectJavaScript but it never ran, and I found that it was because the tag is rendered as self-closing <script src='/script.js' type='text/javascript' />.

The fix was to change it to <script src='/script.js' type='text/javascript'></script>.

Updated SwaggerPluginTest case to assert the closed form.
I also verified locally that an injected script now executes.

@dzikoysk
dzikoysk merged commit d718413 into javalin:main Sep 21, 2026
2 checks passed
@dzikoysk

Copy link
Copy Markdown
Member

Sorry for a late response, I just came back from holidays 🌴 Nice catch, thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants