Hi,
We found that scripts are executable for all input fields.
Can I block that feature?
- Trigger build.
- Move build overview > Edit Description > "" > save
- Refresh page.
- "Alert XSS"
Hi,
We found that scripts are executable for all input fields.
Can I block that feature?
Applications like QB should be used in a trust environment, and I think such issue is tolerable. Even if this is disabled, you still can not prevent users from running arbitrary logic as long as they are allowed to create configurations, as they can checkout from any desired source.