From d6c7306f44ca66157819bd949d0d492d459ec6dc Mon Sep 17 00:00:00 2001 From: Mostafa Lavaei Date: Fri, 31 Jan 2020 17:26:08 +0330 Subject: [PATCH] Update Angular dangerous functions --- .gitignore | 1 + Pattern-Matching/dangerous-functions-angular.txt | 6 ++++++ 2 files changed, 7 insertions(+) diff --git a/.gitignore b/.gitignore index 8ab2fe8c..4183a8ca 100644 --- a/.gitignore +++ b/.gitignore @@ -1,3 +1,4 @@ .DS_Store .*.icloud .gitkeep +.idea diff --git a/Pattern-Matching/dangerous-functions-angular.txt b/Pattern-Matching/dangerous-functions-angular.txt index 3e9b34b7..e1b9e168 100644 --- a/Pattern-Matching/dangerous-functions-angular.txt +++ b/Pattern-Matching/dangerous-functions-angular.txt @@ -1,8 +1,14 @@ +# Angular pipes bypassSecurityTrustHtml bypassSecurityTrustScript bypassSecurityTrustStyle bypassSecurityTrustUrl bypassSecurityTrustResourceUrl + +# Angular inputs +[innerHTML] //Insert given HTML without escaping dangerous characters + +# angular.js (aka Angular 1) trustAsHtml $eval $evalAsync