kopia lustrzana https://github.com/c9/core
Merge pull request +7970 from c9/fix-javascript-token
Make sure generated tokens are never valid JavaScriptpull/117/merge
commit
a65656baee
|
@ -8,5 +8,8 @@ module.exports = function(length) {
|
||||||
.toString("base64")
|
.toString("base64")
|
||||||
.replace(/[^a-zA-Z0-9]/g, "");
|
.replace(/[^a-zA-Z0-9]/g, "");
|
||||||
}
|
}
|
||||||
return uid.slice(0, length);
|
// HACK: make sure unique id is never syntactically valid JavaScript
|
||||||
|
// See http://balpha.de/2013/02/plain-text-considered-harmful-a-cross-domain-exploit/
|
||||||
|
uid = "9c" +uid.slice(0, length - 2);
|
||||||
|
return uid;
|
||||||
};
|
};
|
Ładowanie…
Reference in New Issue