view tests/ahead.ur @ 2116:ebfaab689570

The 2nd half of proper CSRF protection related to environment variables
author Adam Chlipala <adam@chlipala.net>
date Thu, 12 Feb 2015 15:09:26 -0500
parents 44f607a7f4cd
children
line wrap: on
line source
fun main () : transaction page = return <xml>
  <head>
    <script code={alert "Hi!"}/>
  </head>
  <body>
    <active code={alert "Bye!"; return <xml/>}/>
  </body>
</xml>