MCPcopy Create free account
hub / github.com/cure53/DOMPurify / _executableFindings

Function _executableFindings

test/test-suite.js:6757–6780  ·  view source on GitHub ↗
(root)

Source from the content-addressed store, hash-verified

6755 /* Collect anything executable reachable from a serialized string, walking
6756 into <template>.content and any activated shadowRoot. */
6757 const _executableFindings = function (root) {
6758 const findings = [];
6759 const visit = (node) => {
6760 if (!node) return;
6761 if (node.nodeType === 1) {
6762 const tag = node.tagName ? node.tagName.toLowerCase() : '';
6763 for (const name of node.getAttributeNames()) {
6764 if (/^on/i.test(name)) findings.push(`${tag}@${name}`);
6765 if (
6766 (name === 'href' || name === 'src' || name === 'xlink:href') &&
6767 /^\s*(?:java|vb)script:/i.test(node.getAttribute(name) || '')
6768 ) {
6769 findings.push(`${tag}@${name}=js`);
6770 }
6771 }
6772 if (tag === 'script') findings.push('script');
6773 if (node.shadowRoot) visit(node.shadowRoot);
6774 if (tag === 'template' && node.content) visit(node.content);
6775 }
6776 for (const child of node.childNodes) visit(child);
6777 };
6778 visit(root);
6779 return findings;
6780 };
6781 const _findingsFromHTML = function (html) {
6782 const holder = document.createElement('div');
6783 holder.innerHTML = html;

Callers 2

_findingsFromHTMLFunction · 0.85
test-suite.jsFile · 0.85

Calls 1

visitFunction · 0.85

Tested by

no test coverage detected