Closed MRoci closed 3 years ago
use Number() instead of parseInt() to validate user input for height and width properties. Since parseInt stops to the first non-digit and return what it had parsed so far it allows to enter input such as 640" onload="alert()
Number()
parseInt()
parseInt
640" onload="alert()
This closes #89
Sorry for the PR flood :grimacing:
Thanks, @MRoci! You PR's are more than welcome!
use
Number()
instead ofparseInt()
to validate user input for height and width properties. SinceparseInt
stops to the first non-digit and return what it had parsed so far it allows to enter input such as640" onload="alert()
This closes #89
Sorry for the PR flood :grimacing: