Carsten Ziegeler created SLING-13313:
----------------------------------------

             Summary: Improve javascript scheme detection in 
XSSAPI.getValidHref()
                 Key: SLING-13313
                 URL: https://issues.apache.org/jira/browse/SLING-13313
             Project: Sling
          Issue Type: Improvement
          Components: XSS Protection API
    Affects Versions: XSS Protection API 2.4.10
            Reporter: Carsten Ziegeler
            Assignee: Carsten Ziegeler
             Fix For: XSS Protection API 2.4.12


We can improve the scheme detection for javascript href to also account for 
whitespace and similar characters which are ignored by browser



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to