Make sure generated tokens are never valid JavaScript

This commit is contained in:
Lennart kats 2015-06-25 10:47:30 +00:00
parent d77d0c2e02
commit 6dd0764e91

5
node_modules/c9/uid.js generated vendored
View File

@ -8,5 +8,8 @@ module.exports = function(length) {
.toString("base64")
.replace(/[^a-zA-Z0-9]/g, "");
}
return uid.slice(0, length);
// HACK: make sure unique id is never syntactically valid JavaScript
// See http://balpha.de/2013/02/plain-text-considered-harmful-a-cross-domain-exploit/
uid = "9c" +uid.slice(0, length - 2);
return uid;
};