XSS and configuration
XSS and configuration
data:image/s3,"s3://crabby-images/41262/412620cf1f30881454cbca8e772d2372c11b18d3" alt="lugus"
Hello,
Is there a way to specify the render configuration (https://datatables.net/manual/security#Cross-Site-Scripting) to avoid XSS attacks if we are using https://datatables.net/manual/options#HTML-5-data-attributes? It seems no, but in case you have a solution, i give a try!
Thank you,
Alban
This question has an accepted answers - jump to answer
This discussion has been closed.
Answers
The
columns.render
needs to execute as a function, and that can't be done with a string from HTML5 attributes - so currently no - you need to use Javascript to use a renderer like this.However, if you are using the HTML5 options, are you not putting the data into the HTML yourself? In which case you'd need to do the HTML escaping yourself anyway.
Allan