diff --git a/.gitignore b/.gitignore index 8ab2fe8c..4183a8ca 100644 --- a/.gitignore +++ b/.gitignore @@ -1,3 +1,4 @@ .DS_Store .*.icloud .gitkeep +.idea diff --git a/Pattern-Matching/dangerous-functions-angular.txt b/Pattern-Matching/dangerous-functions-angular.txt index 3e9b34b7..e1b9e168 100644 --- a/Pattern-Matching/dangerous-functions-angular.txt +++ b/Pattern-Matching/dangerous-functions-angular.txt @@ -1,8 +1,14 @@ +# Angular pipes bypassSecurityTrustHtml bypassSecurityTrustScript bypassSecurityTrustStyle bypassSecurityTrustUrl bypassSecurityTrustResourceUrl + +# Angular inputs +[innerHTML] //Insert given HTML without escaping dangerous characters + +# angular.js (aka Angular 1) trustAsHtml $eval $evalAsync