dontcallmedom / webidl-checker

This is the source code for the W3C on-line WebIDL checker, a tool verify the correctness of WebIDL fragments embedded in HTML documents.
4 stars 2 forks source link

Audit 2014 02 #12

Closed brettcs closed 10 years ago

brettcs commented 10 years ago

This pull request fixes XSS vulnerabilities and ways to crash the script. See individual commit messages for more details.

brettcs commented 10 years ago

Read the full commit message, it explains all the details. I agree that it's not ideal, and there are other solutions we could consider, but the alternatives were bigger and I wasn't sure what direction would be best. I went with this one as the simplest.

dontcallmedom commented 10 years ago

sorry, I had missed the detailed commit message; diving into it now :)