Preventing HTML and Script injections in Javascript

后端 未结 7 1800
粉色の甜心
粉色の甜心 2020-12-04 13:12

Assume I have a page with an input box. The user types something into the input box and hits a button. The button triggers a function that picks up the value typed into the

7条回答
  •  一向
    一向 (楼主)
    2020-12-04 13:46

    You can encode the < and > to their HTML equivelant.

    html = html.replace(//g, ">");
    

    How to display HTML tags as plain text

提交回复
热议问题