Skip to content

Conversation

@badwriter123
Copy link
Contributor

@badwriter123 badwriter123 commented Aug 18, 2025

Description (#40780)

Hello,
For the file --> files/en-us/web/security/attacks/xss/index.md , I fixed the contradiction in the “Document contexts” section. I have updated the example to use a working payload (onmouseover=alert(1) or backticks). I also corrected the unquoted class example to demonstrate real attribute injection and specified that quoting the placeholder prevents it. No other sections were changed.

Motivation

I wanted to remove the contradiction and make the examples accurate and unambiguous.

@badwriter123 badwriter123 requested a review from a team as a code owner August 18, 2025 17:29
@badwriter123 badwriter123 requested review from hamishwillee and removed request for a team August 18, 2025 17:29
@github-actions github-actions bot added Content:Security Security docs size/xs [PR only] 0-5 LoC changed labels Aug 18, 2025
@github-actions
Copy link
Contributor

github-actions bot commented Aug 18, 2025

Preview URLs

(comment last updated: 2025-08-18 23:35:58)

@github-actions github-actions bot added size/s [PR only] 6-50 LoC changed and removed size/xs [PR only] 0-5 LoC changed labels Aug 18, 2025
Copy link
Collaborator

@hamishwillee hamishwillee left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you. I think this is better.

@hamishwillee hamishwillee merged commit 18d2846 into mdn:main Aug 18, 2025
8 checks passed
@badwriter123 badwriter123 deleted the docs/xss-document-content-fix branch August 19, 2025 03:12
estelle pushed a commit that referenced this pull request Aug 19, 2025
…40786)

* docs(xss): clarify attribute-context examples and fix contradiction

* Update files/en-us/web/security/attacks/xss/index.md

---------

Co-authored-by: Hamish Willee <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Content:Security Security docs size/s [PR only] 6-50 LoC changed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants