Merge pull request #388 from Lavaei/master

Add innerHTML as dangerous input in Angular 2+
This commit is contained in:
g0tmi1k 2020-02-13 14:47:41 +00:00 committed by GitHub
commit 709d6ebeb5
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
2 changed files with 7 additions and 0 deletions

1
.gitignore vendored
View file

@ -1,3 +1,4 @@
.DS_Store .DS_Store
.*.icloud .*.icloud
.gitkeep .gitkeep
.idea

View file

@ -1,8 +1,14 @@
# Angular pipes
bypassSecurityTrustHtml bypassSecurityTrustHtml
bypassSecurityTrustScript bypassSecurityTrustScript
bypassSecurityTrustStyle bypassSecurityTrustStyle
bypassSecurityTrustUrl bypassSecurityTrustUrl
bypassSecurityTrustResourceUrl bypassSecurityTrustResourceUrl
# Angular inputs
[innerHTML] #Insert given HTML without escaping dangerous characters
# angular.js (aka Angular 1)
trustAsHtml trustAsHtml
$eval $eval
$evalAsync $evalAsync