TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

The Blessing of the Strings

31 点作者 lumpa大约 1 年前

3 条评论

mrkeen大约 1 年前
&gt; You can think of TrustedHTML as an interface indicating that a string has been somehow specially &quot;blessed&quot; as safe... Sanitized.<p>Unfortunate naming. &quot;Trusted&quot; is one of those words which has taken on its own opposite as a meaning. Like &quot;redundant&quot; or &quot;cope&quot;.<p>This feature would be Checked&#x2F;Validated&#x2F;Trustworthy&#x2F;Safe. Values would end up in this state if you did not trust them and needed to check them.
评论 #39963071 未加载
评论 #39964450 未加载
评论 #39966047 未加载
评论 #39964364 未加载
wavemode大约 1 年前
I&#x27;m not quite sure I follow the theat model here?<p>&gt; But wait... can&#x27;t someone come along then and just create a more lenient policy called default? No! That will throw an exception!<p>Who is &quot;someone&quot; in this situation? And why are they able to execute arbitrary JavaScript code in the user&#x27;s browser, yet the user is somehow protected by a string sanitization policy?
评论 #39966778 未加载
评论 #39964836 未加载
评论 #39966786 未加载
oasisaimlessly大约 1 年前
TL;DR: Perl&#x27;s taint mode is coming to JavaScript.
评论 #39967380 未加载
评论 #39966868 未加载