Forums » Chit-chat » does it even has bbcode

1 2 3 4 5 6
Protocol whitelisting as an xss prevention measure is pretty solid.

I totally agree with trying to define strong rules and not using cleaning libraries as they greatly increase server load.

Last edited: 23 January 2014 12:22am

Funny Picture" onload="console.log(document.cookie)
Reply
Added a whitelist. It handles everything you've thrown at it so far (with the exception of javas­cript:alert("xss"), which does nothing useful).
Reply
Also looks like I accidentally nuked the edit button. Fixing...
Reply