Avoid using JavaScript in URLs
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
ID: javascript-best-practices/no-script-url
Language: JavaScript
Severity: Notice
Category: Best Practices
Description
JavaScript URLs are evaluated the same way eval
is executed. This can lead to arbitrary code execution.
Non-Compliant Code Examples
var a = 'javascript:void(0);';
var a = 'javascript:';
var a = `javascript:`;
var a = `JavaScript:`;
Compliant Code Examples
var a = 'Hello World!';
var a = 10;
var url = 'xjavascript:'
var url = `xjavascript:`
var url = `${foo}javascript:`
var a = foo`javaScript:`;
Seamless integrations. Try Datadog Code Analysis