mirror of
https://github.com/tenrok/axios.git
synced 2026-06-05 16:42:32 +03:00
29da6b24db
* Fixes issue where XSS scripts attacks were possible via the URL * Fix error * Move throwing error up * Add specs and make regex cover more xss cases
7 lines
174 B
JavaScript
7 lines
174 B
JavaScript
'use strict';
|
|
|
|
module.exports = function isValidXss(requestURL) {
|
|
var xssRegex = /(\b)(on\S+)(\s*)=|javascript|(<\s*)(\/*)script/gi;
|
|
return xssRegex.test(requestURL);
|
|
};
|