const messageText = inputTextBox.value.replace(/<\/?[^>]+(>|$)/g, "");
var $newdiv = $('<div class="' + messageDivClass + '"><p>' + messageText + '<p/><div/>').css({
'opacity': '0.95'
}); const messageText = inputTextBox.value.replace(/<\/?[^>]+(>|$)/g, "");
var $newdiv = $('<div class="' + messageDivClass + '"><p>' + messageText + '<p/><div/>').css({
'opacity': '0.95'
});Both with jQuery:
const $newdiv = $('<div>')
.addClass(messageDivClass)
.text(inputTextBox.value)
.css({'opacity': '0.95'});
and without: const newdiv = document.createElement('div');
newdiv.classList.add(messageDivClass);
newdiv.innerText = inputTextBox.value;
newdiv.style.opacity = '0.95';Unfortunately I'm quite new to full stack. ~1.5 months ago I didn't know a lick of HTML (let alone CSS, JS, any backend framework, AWS, etc), and I'm making lots of mistakes along the way. Currently trying to figure out how to improve my DB performance as Spring's default pagination seems to be quite slow and my site is getting hugged to death at the moment. If anyone has any tips for that especially I'm all ears.
At any rate, your suggestion seems easy enough to put in, so I'll put it in ASAP! Thanks again
Found one potentially good stackoverflow to dig into so far https://stackoverflow.com/questions/44021665/why-is-a-pagina...
I would like to use this idea on a project of mine.
What prevents me from just calling "postMessage" directly myself, which does nothing to prevent the "sanitation" that the replace function call there is supposed to do?
Please sanitize messages on the server instead.
As an exercise I'd love it someone actually posted a payload to exploit that regex.