hundreds-camera-24900
06/28/2022, 2:55 PMmysterious-toddler-20573
06/28/2022, 3:33 PMmysterious-toddler-20573
06/28/2022, 3:33 PMtall-dinner-62086
06/28/2022, 3:39 PMhundreds-camera-24900
06/28/2022, 4:01 PMgorgeous-ghost-95789
06/28/2022, 4:03 PMmysterious-toddler-20573
06/28/2022, 4:11 PMearly-australia-38728
06/28/2022, 4:16 PMearly-australia-38728
06/28/2022, 4:17 PMtall-dinner-62086
06/28/2022, 4:18 PMearly-australia-38728
06/28/2022, 4:18 PMtall-dinner-62086
06/28/2022, 4:19 PMtall-dinner-62086
06/28/2022, 4:19 PMearly-australia-38728
06/28/2022, 4:20 PMearly-australia-38728
06/28/2022, 4:30 PMearly-australia-38728
06/28/2022, 4:54 PMearly-australia-38728
06/28/2022, 4:56 PMcalm-ice-23682
06/28/2022, 9:03 PMripe-action-67367
06/28/2022, 9:15 PMcalm-ice-23682
06/28/2022, 9:34 PMgorgeous-ghost-95789
06/29/2022, 2:21 AMhx-get
(et all) from? Seems like hx-get
-info from an undetermined URL is going to be a security hole no matter what you do.worried-hair-75253
06/29/2022, 2:24 AMhundreds-camera-24900
06/29/2022, 3:23 AMhundreds-camera-24900
06/29/2022, 3:24 AMrefined-waiter-90422
06/29/2022, 4:17 AMjavascript:
js:
data:
vbscript:
file:
refined-waiter-90422
06/29/2022, 4:18 AM.
not just remove. Example: javascriptjavascript::alert('yo')
becomes javascript:alert('yo')
= Ruh roh.refined-waiter-90422
06/29/2022, 4:18 AMrefined-waiter-90422
06/29/2022, 4:20 AMpython
output = output.lower()
for target in ['javascript:','js:','vbscript:','data:','file:']:
output = output.replace(target, '.')
That's what you want, basically, on the backend.