##// END OF EJS Templates
Fix XSS reported on Security list...
Fix XSS reported on Security list No CVE-ID yet August 18, 2015 ----- Reported to Quantopian by Juan Broullón <thebrowfc@gmail.com>... If you create a new folder in the iPython file browser and set Javascript code as its name the code injected will be executed. So, if I create a folder called "><img src=x onerror=alert(document.cookie)> and then I access to it, the cookies will be prompted. The XSS code is also executed if you access a link pointing directly at the folder. jik ------
Matthias Bussonnier -
r21633:3ab41641
Show More
Name Size Modified Last Commit Author
/ git-hooks
README.md Loading ...
install-hooks.sh Loading ...
post-checkout Loading ...
post-merge Loading ...

git hooks for IPython

add these to your .git/hooks

For now, we just have post-checkout and post-merge,
both of which update submodules and attempt to rebuild css sourcemaps,
so make sure that you have a fully synced repo whenever you checkout or pull.

To use these hooks, run ./install-hooks.sh.
If you havn't initialised and updated the submodules manually, you will then need to run git checkout master to activate the hooks (even if you already have master checked out).