Carsten Ziegeler created SLING-13313:
----------------------------------------
Summary: Improve javascript scheme detection in
XSSAPI.getValidHref()
Key: SLING-13313
URL: https://issues.apache.org/jira/browse/SLING-13313
Project: Sling
Issue Type: Improvement
Components: XSS Protection API
Affects Versions: XSS Protection API 2.4.10
Reporter: Carsten Ziegeler
Assignee: Carsten Ziegeler
Fix For: XSS Protection API 2.4.12
We can improve the scheme detection for javascript href to also account for
whitespace and similar characters which are ignored by browser
--
This message was sent by Atlassian Jira
(v8.20.10#820010)