summaryrefslogtreecommitdiff
path: root/share/www/script/couch_test_runner.js
diff options
context:
space:
mode:
authorJan Lehnardt <jan@apache.org>2010-11-02 22:16:18 +0000
committerJan Lehnardt <jan@apache.org>2010-11-02 22:16:18 +0000
commit871e2617e32fb305b9a4e16e560e270a7ef84ffc (patch)
tree8c233b348045a46484c7405590900d1afdfb5a6c /share/www/script/couch_test_runner.js
parentb49ac86e9ac820ff327d132e418f0df5e0f772c8 (diff)
Escape URL and cookie input.
git-svn-id: https://svn.apache.org/repos/asf/couchdb/trunk@1030261 13f79535-47bb-0310-9956-ffa450edef68
Diffstat (limited to 'share/www/script/couch_test_runner.js')
-rw-r--r--share/www/script/couch_test_runner.js7
1 files changed, 7 insertions, 0 deletions
diff --git a/share/www/script/couch_test_runner.js b/share/www/script/couch_test_runner.js
index 2eab9c16..56787e9a 100644
--- a/share/www/script/couch_test_runner.js
+++ b/share/www/script/couch_test_runner.js
@@ -14,6 +14,13 @@
function loadScript(url) {
+ // disallow loading remote URLs
+ if((url.substr(0, 7) == "http://")
+ || (url.substr(0, 2) == "//")
+ || (url.substr(0, 5) == "data:")
+ || (url.substr(0, 11) == "javsacript:")) {
+ throw "Not loading remote test scripts";
+ }
if (typeof document != "undefined") document.write('<script src="'+url+'"></script>');
};