Skip to content

【セキュリティ】ユーザーが入力しているテキストを扱う場合には注意が必要です! #9

Description

@ms2sato

tweets.jsonの内容を画面に出していると思いますが、名前、本文ともにユーザーが自由に入力できる想定ですね(Twitterのようなアプリを想定しています)。

実は今のコードには「クロスサイトスクリプティング」という攻撃に対して脆弱性があります。さて、クロスサイトスクリプティングはどんな攻撃で、どのように守ると良いのでしょうか。

時間のあるときに調べておいてください。

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions