Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

test: Add regression test for XSS via missing attribute escaping #441

Merged
merged 1 commit into from
Jun 29, 2021

Conversation

tosmolka
Copy link
Contributor

Adding unit test for escaping of double quotes in attribute value to avoid regression and potential XSS.

I was recently doing root cause analysis for a security incident that was caused by issue in dom-serializer@0.1.1. The issue is known and has been fixed in newer versions. This PR adds unit test for this particular case to avoid accidental regression in the future.

@fb55 fb55 changed the title Add unit test for XSS via missing attribute escaping to avoid regression test: Add regression test for XSS via missing attribute escaping Jun 29, 2021
@fb55 fb55 merged commit dc550c2 into cheeriojs:master Jun 29, 2021
@fb55
Copy link
Member

fb55 commented Jun 29, 2021

Thanks a lot @tosmolka!

@tosmolka tosmolka deleted the tosmolka/test-attr-escaping branch June 30, 2021 11:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants