English 中文(简体)
i m 试图进行卫生工作,但它没有工作
原标题:i m trying to sanitize but it doesn t work

i m 试图在将它输入数据库之前使html窒息性,即使用先质-htmlnpm包,但它没有工作

if (noteContent) {
  const resultContent = sanitize(noteContent);
  console.log(resultContent);
} else {
  setErrorMessages((prevState) => ["note content cannot be empty"]);
}

here when i m entering <img src=? onerror="alert( hello )" />
it returns:

<p><img src=? onerror="alert( hello )" /></p>  

难道看不错什么?

问题回答

根据上查阅的文件,你正在研究的职能应当称为sanitizeHtml(,而不是sanitize()。

However, if you read closely, per default it does allow quite some html tags and attributes listed here: https://github.com/apostrophecms/sanitize-html?tab=readme-ov-file#default-options

为了进一步限制,遵循文件

// Allow only a super restricted set of tags and attributes
const clean = sanitizeHtml(dirty, {
  allowedTags: [  b ,  i ,  em ,  strong ,  a  ],
  allowedAttributes: {
     a : [  href  ]
  },
  allowedIframeHostnames: [ www.youtube.com ]
});

举例来说,如果是这样的话:

if (noteContent) {
  const resultContent = sanitizeHtml(noteContent, {
    allowedTags: [], 
    allowedAttributes: {}
  });
  console.log(resultContent);
} else {
  setErrorMessages((prevState) => ["note content cannot be empty"]);
}

另见,文件





相关问题
what is wrong with this mysql code

$db_user="root"; $db_host="localhost"; $db_password="root"; $db_name = "fayer"; $conn = mysqli_connect($db_host,$db_user,$db_password,$db_name) or die ("couldn t connect to server"); // perform query ...

Users asking for denormalized database

I am in the early stages of developing a database-driven system and the largest part of the system revolves around an inheritance type of relationship. There is a parent entity with about 10 columns ...

Easiest way to deal with sample data in Java web apps?

I m writing a Java web app in my free time to learn more about development. I m using the Stripes framework and eventually intend to use hibernate and MySQL For the moment, whilst creating the pages ...

join across databases with nhibernate

I am trying to join two tables that reside in two different databases. Every time, I try to join I get the following error: An association from the table xxx refers to an unmapped class. If the ...

How can I know if such value exists in database? (ADO.NET)

For example, I have a table, and there is a column named Tags . I want to know if value programming exists in this column. How can I do this in ADO.NET? I did this: OleDbCommand cmd = new ...

Convert date to string upon saving a doctrine record

I m trying to migrate one of my PHP projects to Doctrine. I ve never used it before so there are a few things I don t understand. In my current code, I have a class similar to this: class ...

热门标签