Quantcast
Channel: SCN: Message List
Viewing all articles
Browse latest Browse all 9129

Re: How to prevent XSS script in input fields

$
0
0

Hi Samuli,

 

Thanks for the helpful link. But in my case, when I do not use HTML encode function, I get following popup.  To avoid this popup, I am trying to encode the  fields name and id .

 

var createdByFullName='';

        var usersList=sap.sopfnd._global.SystemDataMgr.getSystemUsers();   

            var foundUser='f';

            for (var j=0; j<usersList.length; j++){

                if(objectDetails.CREATEDBY==usersList[j].USER_ID){

                    foundUser='t';       

                    createdByFullName= encodeURI(usersList[j].NAME) + " ("+  encodeURI(usersList[j].USER_ID) +")";

                }

                if(foundUser=='t'){

                    break;

                }

            }

 

Please advise, how do I prevent this popup.

 

Thanks & Regards

Uday


Viewing all articles
Browse latest Browse all 9129

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>