4 ms·
Using template literals to represent html is a security issue. If the state comes from the user, they can add script tags into the html. People try to solve thi
by leonardopainter 5y ago
Using template literals to represent html is a security issue. If the state comes from the user, they can add script tags into the html. People try to solve this with tagged templates, but then if you forget the tag, you have a security issue again. Lit checks for this, but the fact that it has to check means it is less secure than not using tagged templates. There are libraries on github for creating sql using tagged templates which have the same security issue. The problem is that if your function works with both tagged templates and plain strings, when you forget to add the tag, you will never know.
- TekMol 5y agoIf the state comes from the user, they can add script tags into the html How is that different with React? And how is it a problem? A rendering engine would set the html of some element to the html I think? This ... document.body.innerHTML='<script>alert(1)</script>'; ...does not execute the script.
- leonardopainter 5y ago<img src='x' onerror='alert(1)'> https://developer.mozilla.org/en-US/docs/Web/API/Element/innerHTML#security_considerations https://developer.mozilla.org/en-US/docs/Web/API/Element/inn...
- TekMol 5y agoTrue. But the same issue with reacts way.
- leonardopainter 5y agoIn terms of the placeholders in JSX, no they are escaped.