aboutsummaryrefslogtreecommitdiffstats
path: root/docs/content/error/compile/nodomevents.ngdoc
diff options
context:
space:
mode:
authorPeter Bacon Darwin2014-02-16 22:02:31 +0000
committerPeter Bacon Darwin2014-02-16 22:02:41 +0000
commit33e1bdc543bcb7875dcc004d487333393670ed2d (patch)
tree7ff1f564ab486f049b7e9e5ad946a6a88bb651b6 /docs/content/error/compile/nodomevents.ngdoc
parent49f90e559ed412402ad7444bc2db2bc1c182ddf5 (diff)
downloadangular.js-33e1bdc543bcb7875dcc004d487333393670ed2d.tar.bz2
chore(errors): rename folders to match namespaces
Diffstat (limited to 'docs/content/error/compile/nodomevents.ngdoc')
-rw-r--r--docs/content/error/compile/nodomevents.ngdoc20
1 files changed, 0 insertions, 20 deletions
diff --git a/docs/content/error/compile/nodomevents.ngdoc b/docs/content/error/compile/nodomevents.ngdoc
deleted file mode 100644
index ed1888c7..00000000
--- a/docs/content/error/compile/nodomevents.ngdoc
+++ /dev/null
@@ -1,20 +0,0 @@
-@ngdoc error
-@name $compile:nodomevents
-@fullName Interpolated Event Attributes
-@description
-
-This error occurs when one tries to create a binding for event handler attributes like `onclick`, `onload`, `onsubmit`, etc.
-
-There is no practical value in binding to these attributes and doing so only exposes your application to security vulnerabilities like XSS.
-For these reasons binding to event handler attributes (all attributes that start with `on` and `formaction` attribute) is not supported.
-
-
-An example code that would allow XSS vulnerability by evaluating user input in the window context could look like this:
-```
-<input ng-model="username">
-<div onclick="{{username}}">click me</div>
-```
-
-Since the `onclick` evaluates the value as JavaScript code in the window context, setting the `username` model to a value like `javascript:alert('PWND')` would result in script injection when the `div` is clicked.
-
-