TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Stealing Bearer Tokens with an Angular Expression Injection

10 点作者 ryhanson超过 9 年前

4 条评论

mikelarned超过 9 年前
It looks like this is only possible when we are mixing server side / client side templates? Enter an expression into input, a user hard refreshes and the expression is rendered into our angular template. Are there any good approaches to always scrubbing expression input on the server side (or just avoid the client side / server side template mix?)
评论 #10622377 未加载
rpkelley超过 9 年前
I bet there are a lot more production angular apps out there than people think that have this vulnerability right now.
评论 #10622331 未加载
bossmojoman超过 9 年前
Crazy, now to go double check all my angular code
lorenmorris超过 9 年前
This is a legitimate comment.