Skip to content

Conversation

david-a-wheeler
Copy link
Contributor

No description provided.

Signed-off-by: David A. Wheeler <[email protected]>
@david-a-wheeler david-a-wheeler marked this pull request as draft October 15, 2024 21:26
res.send must *NOT* be used with untrusted user code,
as this leads to XSS vulnerabilities.
Use res.render instead. See:

* https://expressjs.com/en/api.html
* https://www.geeksforgeeks.org/express-js-res-render-function/
* https://semgrep.dev/docs/cheat-sheets/express-xss

Signed-off-by: David A. Wheeler <[email protected]>
Signed-off-by: David A. Wheeler <[email protected]>
Signed-off-by: David A. Wheeler <[email protected]>
Signed-off-by: David A. Wheeler <[email protected]>
Signed-off-by: David A. Wheeler <[email protected]>
@david-a-wheeler david-a-wheeler marked this pull request as ready for review October 15, 2024 22:13
Allow sub-conditions to be surrounded by parentheses.

Signed-off-by: David A. Wheeler <[email protected]>
@david-a-wheeler david-a-wheeler merged commit fd01531 into main Oct 17, 2024
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant