jeudi 18 juin 2015

Simple client side markdown javascript library that is not vulnerbale to XSS

Is there any simple and fast markdown library that is not vulnerable to XSS attacks? That could be used with ember.js, i've checked couple of popular ones like marked or showdown and they are vulnerable.

If not, what is the proper/common way of making one not vulnerable to XSS attacks? Which sanitize library is commonly used ? I do not need any custom html made by user, only markdown.




Aucun commentaire:

Enregistrer un commentaire