kopia lustrzana https://github.com/c9/core
Merge pull request +7970 from c9/fix-javascript-token
Make sure generated tokens are never valid JavaScriptpull/117/merge
commit
a65656baee
|
@ -8,5 +8,8 @@ module.exports = function(length) {
|
|||
.toString("base64")
|
||||
.replace(/[^a-zA-Z0-9]/g, "");
|
||||
}
|
||||
return uid.slice(0, length);
|
||||
// HACK: make sure unique id is never syntactically valid JavaScript
|
||||
// See http://balpha.de/2013/02/plain-text-considered-harmful-a-cross-domain-exploit/
|
||||
uid = "9c" +uid.slice(0, length - 2);
|
||||
return uid;
|
||||
};
|
Ładowanie…
Reference in New Issue