joewalnes / filtrex

A simple, safe, JavaScript Filter Expression compiler for end-users
MIT License
1.05k stars 74 forks source link

Fix security holes #19

Closed cshaa closed 6 years ago

cshaa commented 6 years ago

Fixes #17, fixes #18. Also fixes errors with trailing backslash in strings. Makes expressions only see own properties of the data object (ie. you cannot return the toString function from an expression).

joewalnes commented 6 years ago

Wow nice find! Thanks!