• Gusted's avatar
    Prevent possible XSS when using jQuery (#18289) · 661d3d28
    Gusted authored
    In the case of misuse or misunderstanding from a developer whereby,
    if `sel` can receive user-controlled data, jQuery `$(sel)` can lead to the
    creation of a new element. Current usage is using hard-coded selectors
    in the templates, but nobody prevents that from expanding to
    user-controlled somehow.
    661d3d28
guidelines-frontend.md 4.96 KB