KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
I want to allow user contributed Javascript in areas of my website. Is this completely insane? Are there any Javascript sanitizer scripts or good regex patterns out there to scan for alerts, iframes, remote script includes and other malicious Javascript? Should this process be manually authorized (by a human checking the Javascript)? Would it be more sensible to allow users to only use a framework (like jQuery) rather than giving them access to actual Javascript? This way it might be easier to monitor. Thanks
Tags (comma-separated)
Save Edits
Cancel