Skip to content

Conversation

xiemaisi
Copy link

@xiemaisi xiemaisi commented Feb 8, 2019

We now highlight the replace call (instead of the regular expression), and the alert message for the case of missing backslash escapes clarifies that it is talking about failure to escape backslashes in the input, not in the replacement text. This hopefully will prevent misunderstandings like this one.

…ation`.

We now highlight the `replace` call (instead of the regular expression), and the alert message for the case of missing backslash escapes clarifies that it is talking about failure to escape backslashes in the input, not in the replacement text.
@xiemaisi xiemaisi added the JS label Feb 8, 2019
@xiemaisi xiemaisi requested a review from a team as a code owner February 8, 2019 09:16
Copy link

@ghost ghost left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@semmle-qlci semmle-qlci merged commit 986afa1 into github:master Feb 8, 2019
@xiemaisi xiemaisi deleted the js/improve-incomplete-sanitization-alerts branch February 11, 2019 09:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants