Xss Prevention

aj-geddes/useful-ai-prompts/skills/xss-prevention

作者 aj-geddes3f5182cfd739无许可证355 个星标收录于 2026年10月8日更新于 2026年10月8日仓库7个月前更新

Prevent Cross-Site Scripting (XSS) attacks through input sanitization, output encoding, and Content Security Policy. Use when handling user-generated content in web applications.

仅含说明

XSS Prevention

Table of Contents

Overview

Implement comprehensive Cross-Site Scripting (XSS) prevention using input sanitization, output encoding, CSP headers, and secure coding practices.

When to Use

  • User-generated content display
  • Rich text editors
  • Comment systems
  • Search functionality
  • Dynamic HTML generation
  • Template rendering

Quick Start

Minimal working example:

javascript
// xss-prevention.jsconst createDOMPurify = require("dompurify");const { JSDOM } = require("jsdom");const he = require("he");
const window = new JSDOM("").window;const DOMPurify = createDOMPurify(window);
class XSSPrevention {  /**   * HTML Entity Encoding - Safest for text content   */  static encodeHTML(str) {    return he.encode(str, {      useNamedReferences: true,      encodeEverything: false,    });  }
  /**   * Sanitize HTML - For rich content   */  static sanitizeHTML(dirty) {    const config = {      ALLOWED_TAGS: [// ... (see reference guides for full implementation)

Reference Guides

Detailed implementations in the references/ directory:

GuideContents
Node.js XSS Prevention [blocked]Node.js XSS Prevention
Python XSS Prevention [blocked]Python XSS Prevention
React XSS Prevention [blocked]React XSS Prevention
Content Security Policy [blocked]Content Security Policy

Best Practices

✅ DO

  • Encode output by default
  • Use templating engines
  • Implement CSP headers
  • Sanitize rich content
  • Validate URLs
  • Use HTTPOnly cookies
  • Regular security testing
  • Use secure frameworks

❌ DON'T

  • Trust user input
  • Use innerHTML directly
  • Skip output encoding
  • Allow inline scripts
  • Use eval()
  • Mix contexts (HTML/JS)

来源与署名

来源:aj-geddes/useful-ai-prompts位于skills/xss-prevention提交3f5182c

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架