3 ms·
It's not nearly as simple as you make it seem: 1. What is "safe content"? That entirely depends on the context in which you're using a particular string. (See
by nbpoole 15y ago
It's not nearly as simple as you make it seem:
1. What is "safe content"? That entirely depends on the context in which you're using a particular string. (See https://www.owasp.org/index.php/XSS_%28Cross_Site_Scripting%29_Prevention_Cheat_Sheet https://www.owasp.org/index.php/XSS_%28Cross_Site_Scripting%... for a summary of the kinds of things you have to think about)
2. The system you're describing is somewhat similar to http://yehudakatz.com/2010/02/01/safebuffers-and-rails-3-0/ http://yehudakatz.com/2010/02/01/safebuffers-and-rails-3-0/. People still find plenty of XSS vulnerabilities in Rails applications.
3. http://lcamtuf.coredump.cx/postxss/ http://lcamtuf.coredump.cx/postxss/