diff options
| author | Chirayu Krishnappa | 2013-06-24 14:14:54 -0700 |
|---|---|---|
| committer | Igor Minar | 2013-07-03 00:03:56 -0700 |
| commit | 5349b20097dc5cdff0216ee219ac5f6e6ef8c219 (patch) | |
| tree | 660ae167076f34018a1ff80565aab6ccdec1d8f4 /src/ng/animator.js | |
| parent | fd87eb0ca5e14f213d8b31280d444dbc29c20c50 (diff) | |
| download | angular.js-5349b20097dc5cdff0216ee219ac5f6e6ef8c219.tar.bz2 | |
fix($parse): disallow access to Function constructor
Enhances sandboxing of Angular Expressions to prevent attacks via:
{}.toString.constructor(alert("evil JS code"))
Diffstat (limited to 'src/ng/animator.js')
0 files changed, 0 insertions, 0 deletions
