File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -29,6 +29,7 @@ var hasRawContent = {
2929 XMP : true ,
3030 IFRAME : true ,
3131 NOEMBED : true ,
32+ NOSCRIPT : true ,
3233 NOFRAMES : true ,
3334 PLAINTEXT : true
3435} ;
@@ -195,8 +196,7 @@ function serializeOne(kid, parent) {
195196 // If an element can have raw content, this content may
196197 // potentially require escaping to avoid XSS.
197198 var upperTag = tagname . toUpperCase ( ) ;
198- if ( hasRawContent [ upperTag ] ||
199- ( upperTag === 'NOSCRIPT' && kid . ownerDocument . _scripting_enabled ) ) {
199+ if ( hasRawContent [ upperTag ] ) {
200200 ss = escapeMatchingClosingTag ( ss , tagname ) ;
201201 }
202202 if ( html && extraNewLine [ tagname ] && ss . charAt ( 0 ) === '\n' ) s += '\n' ;
@@ -214,8 +214,7 @@ function serializeOne(kid, parent) {
214214 else
215215 parenttag = '' ;
216216
217- if ( hasRawContent [ parenttag ] ||
218- ( parenttag === 'NOSCRIPT' && parent . ownerDocument . _scripting_enabled ) ) {
217+ if ( hasRawContent [ parenttag ] ) {
219218 s += kid . data ;
220219 } else {
221220 s += escape ( kid . data ) ;
Original file line number Diff line number Diff line change @@ -180,13 +180,11 @@ exports.styleMatchingClosingTagSkipsUnclosedCommentedContent = function () {
180180} ;
181181
182182exports . noscriptMatchingClosingTagInRawText = function ( ) {
183- // Use a parsed document so `_scripting_enabled` is true, matching how
184- // Angular SSR / platform-server uses domino. With scripting enabled,
185183 // <noscript> is a raw-text element on serialization and its text data
186184 // must have any `</noscript` closing-tag prefix escaped, otherwise an
187185 // attacker-controlled text payload can break out and inject a live
188186 // <script> sibling in the receiving browser.
189- const document = domino . createDocument ( '<!doctype html><html><body></body></html> ' ) ;
187+ const document = domino . createDocument ( '' ) ;
190188 const noscript = document . createElement ( 'noscript' ) ;
191189 noscript . textContent = 'abc</noscript><script>alert(1)</script>' ;
192190 document . body . appendChild ( noscript ) ;
You can’t perform that action at this time.
0 commit comments