I built a plugin for TinyMCE for a client to handle citations within the resource content field editor in Manager. I'll explain the set up as briefly as I can before I get to the problem and the solution I'm using at the moment.
The Editor uses a custom module ('Citations') to enter all of the cited sources used on the site. All data sent to the database uses
$modx->db->escape($_REQUEST['param'])
before INSERT or UPDATE.
My TinyMCE plugin uses that data to populate a select field which the Editor uses to select the citation source. The citation is inserted into the #content at the cursor location and the source is added to <div#sources />. The plugin will then renumber the citations and reorder and renumber the sources so that everything matches up.
A php script called tinymce.citations.php outputs the TinyMCECitationList js variable that the plugin relies on. (This was all based on the tinymce.linklist.php script that is included with Evo installation of TinyMCE).
The php script pulls the data from the table the array of JSON strings (via json_encode).
Today I entered in a couple of new citations. One of them had a title with "Authors' Financial...". This broke it.
I would get and 'Unexpected Identifier' error in console and viewing tinymce.citations.php showed the single-quote as the culprit. It wasn't escaped. All of my double-quotes were properly escaped (there is an entry with a title that has a quoted phrase).
After trying every method I could find, I settled on simply running foreach() through the array and replacing any single-quotes with
in the value (the space is in there to prevent it from becoming a '). I also perform the $modx->db->escape function on the data being json_encod(ed) as the double-quotes were also breaking it early on.
$output = json_encode($modx->db->escape($data));
Everything works now, but this feels pretty hacky to me and wanted to know how others have solved this problem.