Avoid XSS vulnerability by being stricter about how the script element
is created.

Change-Id: I186915ac978fe02fd0bbb93ae8c9a9dd6d8e9d5b
Review-Link: https://gwt-review.googlesource.com/#/c/1250/


git-svn-id: https://google-web-toolkit.googlecode.com/svn/trunk@11385 8db76d5a-ed1c-0410-87a9-c151d255dfc7
6 files changed