but, what's the actual issue?
XSS?
what's the vector attack here?
where the `text` comes from?
XSS?
what's the vector attack here?
where the `text` comes from?
edit. oh I see, somebody can overwrite other params, yea?
I did assume the example was client side, but it might not be. The server may be using it to avoid adding a comment to a database if it's abusive. URLSearchParams exists in Node too https://nodejs.org/api/url.html#url_class_urlsearchparams. There are fetch polyfills available, but the plan is to add it to node.
text="foo&sendPasswordTo=hacker" or text="foo&admin=1"
You can imagine a potentially dangerous parameter and value being passed.
People can already send whatever body they want to your API endpoint. Your client side cleaning won't matter