P
P
Pianist2016-06-27 10:28:43
JavaScript
Pianist, 2016-06-27 10:28:43

How to escape tags in Angularjs?

The task is to output a string, through ng-bind-html only the br, img tags, and escape all the rest, for example <script></script>.
And yet, if you display img onload=somefunc(), you can make an xss attack in this way? In general, you need to display the img tag only for emoji
Found a solution, but only the br tag https://toster.ru/q/177959/

Answer the question

In order to leave comments, you need to log in

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question