Skip to content

Escape semi colons in directive source lists#419

Merged
oreoshake merged 3 commits intomasterfrom
escape-semi-colons
Jan 21, 2020
Merged

Escape semi colons in directive source lists#419
oreoshake merged 3 commits intomasterfrom
escape-semi-colons

Conversation

@oreoshake
Copy link
Contributor

Reported in #418 by @mvgijssel we allow semicolons in directive source list values. The semicolons act as delimiters in CSP leading to undesired and possibly malicious behavior.

I think this is a harmless way of addressing the issue but I've added a deprecation warning indicating it will break with the next release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant