Alex Rivera | Logout

Is it possible to sanitize Javascript code?

Asked 2010-08-25T23:43:46.527
10

I want to allow user contributed Javascript in areas of my website.

  1. Is this completely insane?
  2. Are there any Javascript sanitizer scripts or good regex patterns out there to scan for alerts, iframes, remote script includes and other malicious Javascript?
  3. Should this process be manually authorized (by a human checking the Javascript)?
  4. Would it be more sensible to allow users to only use a framework (like jQuery) rather than giving them access to actual Javascript? This way it might be easier to monitor.

Thanks

Edit
Report

1 Answer

3

Take a look at Google Caja:

Caja allows websites to safely embed DHTML web applications from third parties, and enables rich interaction between the embedding page and the embedded applications. It uses an object-capability security model to allow for a wide range of flexible security policies, so that the containing page can effectively control the embedded applications' use of user data and to allow gadgets to prevent interference between gadgets' UI elements.

answered 2010-08-25T23:54:00.257

Your Answer