No Cross Site Scripting prevention
- Dominant language
- JavaScript
- Stars
- 389
- Forks
- 140
- PR merge metrics
- No merged PRs in 30d
Description
As far as I could see there is no way to protect myself from cross-site scripting with this extension, am I right? If so, the package documentation could at least need some warnings for users of this extension ...
##
---
Want to back this issue? **[Post a bounty on it!](https://www.bountysource.com/issues/8656835-no-cross-site-scripting-prevention?utm_campaign=plugin&utm_content=tracker%2F332251&utm_medium=issues&utm_source=github)** We accept bounties via [Bountysource](https://www.bountysource.com/?utm_campaign=plugin&utm_content=tracker%2F332251&utm_medium=issues&utm_source=github).
Contributor guide
No contributing guide indexed for this repository
Research direction
The issue does not name a file, test, or entry point. First inspect the extension's handling of rendered Markdown and existing package documentation, then establish whether an XSS protection gap exists; done means documenting the relevant risk and user guidance if the concern is confirmed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- django, javascript
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100