Forbid JavaScript in links to the bounce app

pull/1/head
yflory 6 years ago
parent fc915e3337
commit 04decacaca

@ -9,6 +9,12 @@ define(['/api/config'], function (ApiConfig) {
window.alert('The bounce application must only be used with a valid href to visit'); window.alert('The bounce application must only be used with a valid href to visit');
return; return;
} }
if (bounceTo.indexOf('javascript:') === 0 ||
bounceTo.indexOf('vbscript:') === 0 ||
bounceTo.indexOf('data:') === 0) {
window.alert('Illegal bounce URL');
return;
}
window.opener = null; window.opener = null;
window.location.href = bounceTo; window.location.href = bounceTo;
}); });

Loading…
Cancel
Save