CacheControl / CacheControl/json-rules-engine
OnSuccess/OnFailure properties as part of the rule - Security Issue
オープン
- 主要言語
- JavaScript
- スター
- 3.1k
- フォーク
- 507
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
There are 2 properties like Onsuccess and Onfailure property which can be a javascript function delegate and it is part of the rule right?
onSuccess: function(event,almanac) { console.log('hello success') },
onFailure : function(event,almanac) { alert('hello failed') }
Is it safe to store this as part of the rule in the database. Because the rule comes from the server to the client this script can be tampered by the hacker and we would end up executing a malicious script. Is that right?
Or Is my understanding wrong? Please confirm
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
評価
この issue はまだ評価されていません。