ofaurax / eotoolbar

Esperanto Toolbar extension for Mozilla Firefox
1 stars 0 forks source link

Warnings in AMO #2

Open ofaurax opened 8 years ago

ofaurax commented 8 years ago
on* attribute being set using setAttribute

Avertissement: To prevent vulnerabilities, event handlers (like 'onclick' and 'onhover') should always be defined using addEventListener.
chrome/content/eotoolbar.js
var info = document.getElementById('eotoolbar-inforss');
info.setAttribute("oncommand",
    "gBrowser.selectedBrowser.loadURI('"+link.textContent+"');");
ofaurax commented 7 years ago

https://addons.mozilla.org/fr/developers/upload/2f45a11622c246329f5834588be71088