Skip to content

Channel.trigger can send ANY data to subscribers without checking #283

@ikasoumen

Description

@ikasoumen

Hi,

I want to broadcast messages including HTML tags, but there is a security problem cause of channel.trigger.
I try to send messages including script tags to all subscribers with browser console, and then they received this message without checking in the server side's controller.
So I wanna disable this function "channel.trigger". Do you have any good Idea?

Thank you for reading.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions