Skip to content

Commit

Permalink
Merge pull request #35 from gtsp233/patch-1
Browse files Browse the repository at this point in the history
validate url to prevent xss
  • Loading branch information
jtaox committed Jan 29, 2024
2 parents d359c16 + e152a59 commit 73ee9ae
Showing 1 changed file with 4 additions and 0 deletions.
4 changes: 4 additions & 0 deletions packages/mtbird-helper-extension/src/helpers.ts
Expand Up @@ -12,6 +12,10 @@ export const generateEventHandler = (store: any, params: IContribute) => {
store.actions.toggleModal(params.feature, params);
break;
case "link":
const isJavaScriptProtocol = /^[\u0000-\u001F ]*j[\r\n\t]*a[\r\n\t]*v[\r\n\t]*a[\r\n\t]*s[\r\n\t]*c[\r\n\t]*r[\r\n\t]*i[\r\n\t]*p[\r\n\t]*t[\r\n\t]*\:/i
if (isJavaScriptProtocol.test(params.href)) {
break;
}
window.open(params.href);
break;
}
Expand Down

0 comments on commit 73ee9ae

Please sign in to comment.