前端防止xss攻擊的方法:
過濾非法字符,例如:
// 過濾XSS反射型漏洞
filterInputTxt: function (html) {
html = html.replace(/(.*<[^>]+>.*)/g,""); // HTML標記
html = html.replace(/([\r\n])[\s]+/g, ""); // 換行、空格
html = html.replace(//g, ""); // HTML注釋
html = html.replace(/['"‘’“”!@#$%^&*{}!¥()()×+=]/g, ""); // 非法字符
html = html.replace("alert","");
html = html.replace("eval","");
html = html.replace(/(.*javascript.*)/gi,"");
if (html === "") {
html = "你好";
}
return html;
}