@opengis/fastify-table
Version:
core-plugins
73 lines (71 loc) • 1.23 kB
JavaScript
const xssInjection = [
'onkeypress=',
'onkeyup=',
'ondblclick=',
'onerror=',
'onmouseover=',
'<meta',
'<script',
'vascript:',
'onkeydown=',
'onmousedown=',
'onmouseenter=',
'onmouseleave=',
'onmousemove=',
'onmouseout=',
'onmouseup=',
'onmousewheel=',
'onpaste=',
'onscroll=',
'onwheel=',
'javascript:',
'\\x',
'eval(',
'onmouseover=',
'action=',
'xlink:',
'allowscriptaccess',
'href=',
'behavior:',
'onreadystatechange=',
'onstart=',
'offline=',
'onabort=',
'onafterprint=',
'onbeforeonload=',
'onbeforeprint=',
'onblur=',
'oncanplay=',
'oncanplaythrough=',
'onchange=',
'onclick=',
'oncontextmenu=',
'ondblclick=',
'ondrag=',
'ondragend=',
'ondragenter=',
'ondragleave=',
'ondragover=',
'ondragstart=',
'ondrop=',
'ondurationchange=',
'onemptied=',
'onended=',
'onerror=',
'onfocus=',
'onformchange=',
'onforminput=',
'onhaschange=',
'oninput=',
'oninvalid=',
'onkeydown=',
'onkeypress=',
'onkeyup=',
'onload=',
'onloadeddata=',
'onloadedmetadata=',
'onloadstart=',
'alert(',
'script:',
];
export default xssInjection;