diff options
| author | Bert JW Regeer <bertjw@regeer.org> | 2015-04-14 00:12:56 -0400 |
|---|---|---|
| committer | Bert JW Regeer <bertjw@regeer.org> | 2015-04-14 00:12:56 -0400 |
| commit | b6ffe51f16d2ea65f2313e99b24185f635a1bf64 (patch) | |
| tree | 3139530ef8c9f1338b7ff42e82630bdb0bc0e4b1 /tox.ini | |
| parent | 81fb26d351168e13c9f0270e1ea7eb9bdecda51c (diff) | |
| download | pyramid-b6ffe51f16d2ea65f2313e99b24185f635a1bf64.tar.gz pyramid-b6ffe51f16d2ea65f2313e99b24185f635a1bf64.tar.bz2 pyramid-b6ffe51f16d2ea65f2313e99b24185f635a1bf64.zip | |
Add some validation for the JSONP callback
The callback variable could be used to arbitrarily inject javascript
into the response object. This validates that the callback doesn't begin
with a number and is standard US ASCII characters, because trying to
make sure the JavaScript function name is actually valid would require
parsing JavaScript itself...
Diffstat (limited to 'tox.ini')
0 files changed, 0 insertions, 0 deletions
