summaryrefslogtreecommitdiff
path: root/tox.ini
diff options
context:
space:
mode:
authorBert JW Regeer <bertjw@regeer.org>2015-04-14 00:12:56 -0400
committerBert JW Regeer <bertjw@regeer.org>2015-04-14 00:12:56 -0400
commitb6ffe51f16d2ea65f2313e99b24185f635a1bf64 (patch)
tree3139530ef8c9f1338b7ff42e82630bdb0bc0e4b1 /tox.ini
parent81fb26d351168e13c9f0270e1ea7eb9bdecda51c (diff)
downloadpyramid-b6ffe51f16d2ea65f2313e99b24185f635a1bf64.tar.gz
pyramid-b6ffe51f16d2ea65f2313e99b24185f635a1bf64.tar.bz2
pyramid-b6ffe51f16d2ea65f2313e99b24185f635a1bf64.zip
Add some validation for the JSONP callback
The callback variable could be used to arbitrarily inject javascript into the response object. This validates that the callback doesn't begin with a number and is standard US ASCII characters, because trying to make sure the JavaScript function name is actually valid would require parsing JavaScript itself...
Diffstat (limited to 'tox.ini')
0 files changed, 0 insertions, 0 deletions