Skip to content

Commit 93823e9

Browse files
authored
Revert "Potential fix for code scanning alert no. 2: Reflected cross-site scripting"
1 parent 362a4a3 commit 93823e9

File tree

1 file changed

+1
-10
lines changed

1 file changed

+1
-10
lines changed

pages/api/display-message.js

Lines changed: 1 addition & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -2,15 +2,6 @@
22
// DO NOT USE IN PRODUCTION
33
// This API endpoint demonstrates XSS vulnerabilities for CodeQL detection
44

5-
function escapeHtml(str) {
6-
return String(str)
7-
.replace(/&/g, '&')
8-
.replace(/</g, '&lt;')
9-
.replace(/>/g, '&gt;')
10-
.replace(/"/g, '&quot;')
11-
.replace(/'/g, '&#39;');
12-
}
13-
145
export default function handler(req, res) {
156
const { message } = req.query;
167

@@ -29,7 +20,7 @@ export default function handler(req, res) {
2920
</head>
3021
<body>
3122
<h1>Your Message:</h1>
32-
<div>${escapeHtml(message)}</div>
23+
<div>${message}</div>
3324
</body>
3425
</html>
3526
`;

0 commit comments

Comments
 (0)