Skip to content

LGTM.com - false positive - XSS #2196

@AlexTereshenkov

Description

@AlexTereshenkov

Description of the false positive

It seems as encodeURIComponent in the encodeURIComponent(window.location.href) should have prevented this to appear as part of the client-side cross-site scripting.

URL to the alert on the project page on LGTM.com

https://lgtm.com/projects/g/web2py/web2py/snapshot/dd7f4f5e26da1a13de3b7dfe3a1847b3bbe40812/files/applications/admin/static/js/share.js?sort=name&dir=ASC&mode=heatmap#xa529f548552a385f:1

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions