DescriptionReverse order of tests in eraseDangerousAttributeIfInjected().
The semicolon-separated case must come first to prevent it from
being handled in the ordinary manner when the string starts with
javascript:, since it need not obey the normal termination rules
when it is first split by semicolons.
BUG=384077
Committed: https://src.chromium.org/viewvc/blink?view=rev&revision=176478
Patch Set 1 #
Messages
Total messages: 5 (0 generated)
|