Reverse order of tests in eraseDangerousAttributeIfInjected().
The semicolon-separated case must come first to prevent it from being handled in the ordinary manner when the string starts with javascript:, since it need not obey the normal termination rules when it is first split by semicolons. BUG=384077 Review URL: https://codereview.chromium.org/346623003 git-svn-id: svn://svn.chromium.org/blink/trunk@176478 bbb929c8-8fbe-4397-9dbb-9b2b20218538
Showing
Please register or sign in to comment