Xss Prevention

aj-geddes/useful-ai-prompts/skills/xss-prevention

作者 aj-geddes3f5182cfd739無授權條款355 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫7 個月前更新

Prevent Cross-Site Scripting (XSS) attacks through input sanitization, output encoding, and Content Security Policy. Use when handling user-generated content in web applications.

僅含說明

XSS Prevention

Table of Contents

Overview

Implement comprehensive Cross-Site Scripting (XSS) prevention using input sanitization, output encoding, CSP headers, and secure coding practices.

When to Use

  • User-generated content display
  • Rich text editors
  • Comment systems
  • Search functionality
  • Dynamic HTML generation
  • Template rendering

Quick Start

Minimal working example:

javascript
// xss-prevention.jsconst createDOMPurify = require("dompurify");const { JSDOM } = require("jsdom");const he = require("he");
const window = new JSDOM("").window;const DOMPurify = createDOMPurify(window);
class XSSPrevention {  /**   * HTML Entity Encoding - Safest for text content   */  static encodeHTML(str) {    return he.encode(str, {      useNamedReferences: true,      encodeEverything: false,    });  }
  /**   * Sanitize HTML - For rich content   */  static sanitizeHTML(dirty) {    const config = {      ALLOWED_TAGS: [// ... (see reference guides for full implementation)

Reference Guides

Detailed implementations in the references/ directory:

GuideContents
Node.js XSS Prevention [blocked]Node.js XSS Prevention
Python XSS Prevention [blocked]Python XSS Prevention
React XSS Prevention [blocked]React XSS Prevention
Content Security Policy [blocked]Content Security Policy

Best Practices

✅ DO

  • Encode output by default
  • Use templating engines
  • Implement CSP headers
  • Sanitize rich content
  • Validate URLs
  • Use HTTPOnly cookies
  • Regular security testing
  • Use secure frameworks

❌ DON'T

  • Trust user input
  • Use innerHTML directly
  • Skip output encoding
  • Allow inline scripts
  • Use eval()
  • Mix contexts (HTML/JS)

來源與署名

來源:aj-geddes/useful-ai-prompts位於skills/xss-prevention提交3f5182c

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架