MCPcopy Create free account
hub / github.com/cure53/DOMPurify / _executableFindings

Function _executableFindings

test/test-suite.js:6644–6667  ·  view source on GitHub ↗
(root)

Source from the content-addressed store, hash-verified

6642 /* Collect anything executable reachable from a serialized string, walking
6643 into <template>.content and any activated shadowRoot. */
6644 const _executableFindings = function (root) {
6645 const findings = [];
6646 const visit = (node) => {
6647 if (!node) return;
6648 if (node.nodeType === 1) {
6649 const tag = node.tagName ? node.tagName.toLowerCase() : '';
6650 for (const name of node.getAttributeNames()) {
6651 if (/^on/i.test(name)) findings.push(`${tag}@${name}`);
6652 if (
6653 (name === 'href' || name === 'src' || name === 'xlink:href') &&
6654 /^\s*(?:java|vb)script:/i.test(node.getAttribute(name) || '')
6655 ) {
6656 findings.push(`${tag}@${name}=js`);
6657 }
6658 }
6659 if (tag === 'script') findings.push('script');
6660 if (node.shadowRoot) visit(node.shadowRoot);
6661 if (tag === 'template' && node.content) visit(node.content);
6662 }
6663 for (const child of node.childNodes) visit(child);
6664 };
6665 visit(root);
6666 return findings;
6667 };
6668 const _findingsFromHTML = function (html) {
6669 const holder = document.createElement('div');
6670 holder.innerHTML = html;

Callers 2

_findingsFromHTMLFunction · 0.85
test-suite.jsFile · 0.85

Calls 1

visitFunction · 0.85

Tested by

no test coverage detected