Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Issue #438 - Improve XSS cheatsheet to address escape/encode confusion #449

Merged
merged 1 commit into from Jul 23, 2020

Conversation

@cdwijayarathna
Copy link
Contributor

@cdwijayarathna cdwijayarathna commented Jul 21, 2020

I have changed the XSS prevention cheatsheet based on the discussion we had at issue #438 .

Basically, I removed word 'escape' where it does not follow the definition at https://owasp.org/www-project-proactive-controls/v3/en/c4-encode-escape-data.

I left a few references to 'escape' as well where I felt it follows the above definition.

Open for discussion

This PR covers issue #438

Copy link
Collaborator

@mackowski mackowski left a comment

LGTM

@mackowski
Copy link
Collaborator

@mackowski mackowski commented Jul 23, 2020

@jmanico reviewed it here: #438 (comment)

@mackowski mackowski merged commit 1dd7787 into OWASP:master Jul 23, 2020
3 checks passed
3 checks passed
link-check
Details
lint
Details
Publishing Check
Details
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Linked issues

Successfully merging this pull request may close these issues.

None yet

2 participants