4 ms·
A lot of people do input validation by disallowing 'bad' characters. The idea is to stop people buying JavaScript in comments, as that would be bad. Just strip
by notauser 17y ago
A lot of people do input validation by disallowing 'bad' characters.
The idea is to stop people buying JavaScript in comments, as that would be bad. Just strip enough characters that you can't do functions and everything will be...
...oops. Hope you remembered to filter out + and [] as well! Never mind, now all your visitors are automatically posting/up-voting spam comments or something similar. Better luck next time.
- raganwald 17y agoCaptain Obvious here again. Doesn't all this go away if you use Javascript to inject untrusted text directly into the DOM rather than rendering it as HTML which is then interpreted by the browser? And if so, it seems to me that there's a fairly obvious way to build that directly into templating engines and meta-languages like HAML.
- mncaudill 17y agoThat would work, but with the downside of lowering the accessibility of your site. Not everyone has JavaScript enabled, and so dynamic insertion of text wouldn't be accommodating to them.
- zackattack 17y agoHow many people don't have JavaScript enabled these days? I guess you have to consider your audience. http://www.w3schools.com/browsers/browsers_stats.asp http://www.w3schools.com/browsers/browsers_stats.asp has some clues.
- mncaudill 17y agoThat's true for people that don't need alternate browsers. It's like, "why build wheelchair ramps outside of businesses when 99.99% of people are able to walk up steps?" http://www.section508.gov/ http://www.section508.gov/