5 ms·
Google-Caja: source-to-source translator for securing Javascript-based content
- nose 16y agoTheir list of typical attack vectors in ES3 is very eye opening: http://code.google.com/p/google-caja/wiki/AttackVectors http://code.google.com/p/google-caja/wiki/AttackVectors http://code.google.com/p/google-caja/w/list?q=label:Attack-Vector http://code.google.com/p/google-caja/w/list?q=label:Attack-V... You can also easily play with the Valija and ES5/3 dialect here http://caja.appspot.com http://caja.appspot.com
- gcb 16y agoThey use that widely in igoogle and orkut apps.
- nose 16y agoIt's opt-in for orkut app developers. It's enabled by default, and enforced on yahoo.com/my.yahoo.com http://developer.yahoo.com/yap/homepage/ http://developer.yahoo.com/yap/homepage/
- cies 16y agoThis is so important for 'us', here on HN. Let me try to explain why: Many here are building SaaS products, and with the SaaS landscape getting ever more crowded we see a lot of SaaS integrations emerge. Have a look at freshbooks for instance. Currently these integrations are usually implemented 'server-side': the server of one web app pulls data from another web app. If we want to allow client-side integrations, that allows a JS plugin to be loaded from another app, the we need to keep security in mind (as this is on purpose cross-site-scripting). This Caja lib seems to provide proper measures to allow these kind of integrations.