Files
codeql/javascript/ql/test/query-tests/Security/CWE-020/IncompleteUrlSchemeCheck.js
2019-11-13 10:27:18 +00:00

7 lines
162 B
JavaScript

function sanitizeUrl(url) {
let u = decodeURI(url).trim().toLowerCase();
if (u.startsWith("javascript:"))
return "about:blank";
return url;
}