4 ms·
If you're considering developing this app further, you might want to take a look at the security of your app. A few minutes and I found quite a few XSS attacks
by Xk 16y ago
If you're considering developing this app further, you might want to take a look at the security of your app. A few minutes and I found quite a few XSS attacks on it.
If you'd like, I can email you all of the attacks I've found so you can fix them.
Edit: XSS isn't all there is to worry about.
- jashkenas 16y agojamesjyu: If you haven't seen Backbone.Model's "escape" method yet, it can help sanitize your model attributes, without having to constantly re-escape them at every use. http://documentcloud.github.com/backbone/#Model-escape http://documentcloud.github.com/backbone/#Model-escape
- bricestacey 16y agoDoes rendering attributes using jQuery's text() method[1] properly sanitize the model attributes too? I ask because I'm making a backbone app and I'm following the same process found in Ben Nolan's mobile app [2] where he does something like this.el.find('h1').text("Editing " + (this.model.getName())); [1] http://api.jquery.com/text/ [2] https://github.com/bnolan/Backbone-Mobile/blob/master/application.js
- jashkenas 16y agoYes. jQuery's text() method will properly escape HTML fragments. It's just a bit more verbose and a bit slower than using .escape("attribute") within a template.
- jamesjyu 16y agoYes, please email at quietwriteapp@gmail.com -- Thanks!
- Xk 16y agoYou're really quite quick at fixing these things -- as I'm creating a demo page to email you, I'm noticing every time I refresh, one of the old attacks doesn't work any more.