Skip to content

Commit e13dbad

Browse files
authored
Merge pull request #25 from BetterMint/alert-autofix-11
Potential fix for code scanning alert no. 11: Reflected server-side cross-site scripting
2 parents 837850f + ef71dda commit e13dbad

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

test/BetterMITM/addons/test_asgiapp.py

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
import asyncio
22
import json
3-
3+
import html
44
import flask
55
from flask import request
66

@@ -27,7 +27,7 @@ def request_check():
2727

2828
@tapp.route("/requestbody", methods=["POST"])
2929
def request_body():
30-
return json.dumps({"body": request.data.decode()})
30+
return json.dumps({"body": html.escape(request.data.decode())})
3131

3232

3333
@tapp.route("/error")

0 commit comments

Comments
 (0)