diff options
author | Jan Lehnardt <jan@apache.org> | 2010-11-02 22:16:18 +0000 |
---|---|---|
committer | Jan Lehnardt <jan@apache.org> | 2010-11-02 22:16:18 +0000 |
commit | 871e2617e32fb305b9a4e16e560e270a7ef84ffc (patch) | |
tree | 8c233b348045a46484c7405590900d1afdfb5a6c /share/www/script/couch_test_runner.js | |
parent | b49ac86e9ac820ff327d132e418f0df5e0f772c8 (diff) |
Escape URL and cookie input.
git-svn-id: https://svn.apache.org/repos/asf/couchdb/trunk@1030261 13f79535-47bb-0310-9956-ffa450edef68
Diffstat (limited to 'share/www/script/couch_test_runner.js')
-rw-r--r-- | share/www/script/couch_test_runner.js | 7 |
1 files changed, 7 insertions, 0 deletions
diff --git a/share/www/script/couch_test_runner.js b/share/www/script/couch_test_runner.js index 2eab9c16..56787e9a 100644 --- a/share/www/script/couch_test_runner.js +++ b/share/www/script/couch_test_runner.js @@ -14,6 +14,13 @@ function loadScript(url) { + // disallow loading remote URLs + if((url.substr(0, 7) == "http://") + || (url.substr(0, 2) == "//") + || (url.substr(0, 5) == "data:") + || (url.substr(0, 11) == "javsacript:")) { + throw "Not loading remote test scripts"; + } if (typeof document != "undefined") document.write('<script src="'+url+'"></script>'); }; |