Mercurial > urweb
annotate tests/naughty.ur @ 1710:540df112ff62
Remove string-valued style attribute, which may allow injection attacks
author | Adam Chlipala <adam@chlipala.net> |
---|---|
date | Sun, 15 Apr 2012 12:40:53 -0400 |
parents | deeeb036c8ed |
children |
rev | line source |
---|---|
adam@1633 | 1 fun main () : transaction page = |
adam@1633 | 2 if naughtyDebug "hello" = 0 then |
adam@1633 | 3 return <xml><body></body></xml> |
adam@1633 | 4 else |
adam@1633 | 5 error <xml>Uhoh!</xml> |
adam@1633 | 6 |
adam@1633 | 7 (*fun main () : transaction page = |
adam@1633 | 8 let |
adam@1633 | 9 val a = naughtyDebug "" |
adam@1633 | 10 in |
adam@1633 | 11 return <xml><body></body></xml> |
adam@1633 | 12 end*) |