4 ms·
I think it is now somewhat disabled. you just need to refresh the page.
by idoco 11y ago
I think it is now somewhat disabled. you just need to refresh the page.
- idoco 11y agoThis is what I did for now msg.text = msg.text.replace('>','') .replace('<','') .replace(';','') .replace('/','') .replace('\\','') .replace('\'','') .replace('\"','') .replace(':"','') .replace('!important',''); I will think of a more clever solution next week :)
- Rygu 11y agoI see an iframe on the page. Right now.
- the-dude 11y agoThis is a naive solution. Pull in some library.
- jpallen 11y agoMake your regexs global, i.e. .replace(/</g, "") (note the g at the end), otherwise only the first instance is replaced. I made it easy for you: https://github.com/idoco/map-chat/pull/1 https://github.com/idoco/map-chat/pull/1
- thekingshorses 11y agovar div = document.createElement('div'); div.textContent = msg; msg.text = div.innerHTML; This should remove all HTML/CSS/Script.
- krapp 11y agoHere is how mustache.js[0] does it: var entityMap = { "&": "&", "<": "<", ">": ">", '"': '"', "'": ''', "/": '/' }; function escapeHtml(string) { return String(string).replace(/[&<>"'\/]/g, function (s) { return entityMap[s]; }); } also document.createTextNode will tell the browser not to render the children as html, whereas appending a dom element and innerHTML will.[1] I'm just assuming that behavior is correct in all browsers though. [0]https://github.com/janl/mustache.js/blob/master/mustache.js#L52 https://github.com/janl/mustache.js/blob/master/mustache.js#... [1]https://jsfiddle.net/1dsygwoj/ https://jsfiddle.net/1dsygwoj/
- idoco 11y agoThanks I added that on top of JsHtmlSanitizer.
- pskocik 11y agoThat's super easy to get around. It only replaces the first occurrence of each.
- idoco 11y agoYou are right that was very silly of me. I got some real XSS filter instead.