[
https://issues.apache.org/jira/browse/SLING-13313?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Carsten Ziegeler resolved SLING-13313.
--------------------------------------
Resolution: Fixed
Improved with
https://github.com/apache/sling-org-apache-sling-xss/commit/f73c46bbd1cae73db13d8e4581d9f1b8d9300b9f
> Improve javascript scheme detection in XSSAPI.getValidHref()
> ------------------------------------------------------------
>
> Key: SLING-13313
> URL: https://issues.apache.org/jira/browse/SLING-13313
> Project: Sling
> Issue Type: Improvement
> Components: XSS Protection API
> Affects Versions: XSS Protection API 2.4.10
> Reporter: Carsten Ziegeler
> Assignee: Carsten Ziegeler
> Priority: Major
> Fix For: XSS Protection API 2.4.12
>
>
> We can improve the scheme detection for javascript href to also account for
> whitespace and similar characters which are ignored by browser
--
This message was sent by Atlassian Jira
(v8.20.10#820010)