{"_id":"secure-filters","_rev":"21-f3b53773bf46da0fc84b7f91f24cb44e","name":"secure-filters","description":"Anti-XSS filters for security","dist-tags":{"latest":"1.1.0"},"versions":{"1.0.3":{"name":"secure-filters","version":"1.0.3","description":"Anti-XSS filters for security","main":"index.js","scripts":{"test":"mocha test.js && mocha-phantomjs -R dot static/test.html"},"homepage":"http://goinstant.github.io/secure-filters/","repository":{"type":"git","url":"git@github.com:goinstant/secure-filters.git"},"author":{"name":"GoInstant Inc., a salesforce.com company"},"license":"BSD-3-Clause","engines":{"node":">= 0.10.0"},"keywords":["security","xss","ejs","escape","encode"],"devDependencies":{"gi-assert":"git://github.com/goinstant/assert.git#v1.0.0","mocha":"1.8.2","mocha-phantomjs":"2.0.2","lodash":"1.3.1","component":"0.18.0","coveralls":"2.3.0","mocha-lcov-reporter":"0.0.1","blanket":"1.1.5"},"bugs":{"url":"https://github.com/goinstant/secure-filters/issues"},"_id":"secure-filters@1.0.3","dist":{"shasum":"79e1805a85438a601c90fd362c5988415d382244","tarball":"https://registry.npmjs.org/secure-filters/-/secure-filters-1.0.3.tgz","integrity":"sha512-I+hcALcuGY7qX4pUlFgiRIEWA81z5IZhyI5H1MxY35lW5cUDZRF+TI8A79BAEnI2MlUjgFILWVeswTneuxFilQ==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCKbpPuStpuWR2yvyVdSVeuj07NhzDubc4/0wk2Pad5eQIhAI2vaLQi3xPUNT1LFugSplPiVh5sZV0udFjCLb3AB54A"}]},"_from":".","_npmVersion":"1.3.11","_npmUser":{"name":"goinstant","email":"support@goinstant.com"},"maintainers":[{"name":"goinstant","email":"support@goinstant.com"}]},"1.0.4":{"name":"secure-filters","version":"1.0.4","description":"Anti-XSS filters for security","main":"index.js","scripts":{"test":"mocha test.js && mocha-phantomjs -R dot static/test.html"},"homepage":"http://goinstant.github.io/secure-filters/","repository":{"type":"git","url":"git@github.com:goinstant/secure-filters.git"},"author":{"name":"GoInstant Inc., a salesforce.com company"},"license":"BSD-3-Clause","engines":{"node":">= 0.10.0"},"keywords":["security","xss","ejs","escape","encode"],"devDependencies":{"gi-assert":"git://github.com/goinstant/assert.git#v1.0.0","mocha":"1.8.2","mocha-phantomjs":"2.0.2","lodash":"1.3.1","component":"0.18.0","coveralls":"2.3.0","mocha-lcov-reporter":"0.0.1","blanket":"1.1.5"},"bugs":{"url":"https://github.com/goinstant/secure-filters/issues"},"_id":"secure-filters@1.0.4","dist":{"shasum":"eaa2a371f706fc38da1bf08cc2ec6638b3ecdb0f","tarball":"https://registry.npmjs.org/secure-filters/-/secure-filters-1.0.4.tgz","integrity":"sha512-KwdTtlcrcj7WNiMHLPTZLJAcV1I+J9Rp+SVtOCMxT+qL3AXjg8kl7+BYYJe7WPrjASpLt9Vroy1DTvV45yJSNw==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIA46Eiml1GXxC1bIz6AzHaCNounFwhho6HuANn5BhwsOAiEAs5N0aGtuBBte5aU042QlvaCpV+boyQcBi6HL8Cc91MM="}]},"_from":".","_npmVersion":"1.3.11","_npmUser":{"name":"goinstant","email":"support@goinstant.com"},"maintainers":[{"name":"goinstant","email":"support@goinstant.com"}]},"1.0.5":{"name":"secure-filters","version":"1.0.5","description":"Anti-XSS filters for security","main":"index.js","scripts":{"test":"mocha test.js && mocha-phantomjs -R dot static/test.html"},"homepage":"http://goinstant.github.io/secure-filters/","repository":{"type":"git","url":"git@github.com:goinstant/secure-filters.git"},"author":{"name":"GoInstant Inc., a salesforce.com company"},"license":"BSD-3-Clause","engines":{"node":">= 0.10.0"},"keywords":["security","xss","ejs","escape","encode"],"devDependencies":{"gi-assert":"git://github.com/goinstant/assert.git#v1.0.0","mocha":"1.8.2","mocha-phantomjs":"2.0.2","lodash":"1.3.1","component":"0.18.0","coveralls":"2.3.0","mocha-lcov-reporter":"0.0.1","blanket":"1.1.5"},"bugs":{"url":"https://github.com/goinstant/secure-filters/issues"},"_id":"secure-filters@1.0.5","dist":{"shasum":"6216a24e495b6693fdd8f511ecc456b93bcba5b0","tarball":"https://registry.npmjs.org/secure-filters/-/secure-filters-1.0.5.tgz","integrity":"sha512-JyCi3dwiuRqdzazb1yLzcdswdt7J8YOEfBLWTidStaX1coxBNywzM6OA9DznBmyLqmKhM14YbEGT741lbvqIIw==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCR7AnBJi9s6b+GL+BzSgyAbK07FBwLBkXO+n54eYaBVwIgcevkDdv/eabaxiLJRdvP5CvccVXdjkdzuS0C+KjQh7I="}]},"_from":".","_npmVersion":"1.3.11","_npmUser":{"name":"goinstant","email":"support@goinstant.com"},"maintainers":[{"name":"goinstant","email":"support@goinstant.com"}]},"1.1.0":{"name":"secure-filters","version":"1.1.0","description":"Anti-XSS filters for security","main":"index.js","scripts":{"test":"`npm bin`/mocha test.js && `npm bin`/mocha-phantomjs -R dot static/test.html"},"homepage":"http://salesforce.github.io/secure-filters/","repository":{"type":"git","url":"git+ssh://git@github.com/salesforce/secure-filters.git"},"author":{"name":"Salesforce.com, Inc."},"license":"BSD-3-Clause","engines":{"node":">= 0.10.0"},"keywords":["security","xss","ejs","escape","encode"],"devDependencies":{"chai":"^1.9.2","mocha":"^1.21.4","mocha-phantomjs":"^4.1.0","underscore":"^1.8.0"},"contributors":[{"name":"Jeremy Stashewsky","email":"jstashewsky@salesforce.com"},{"name":"Amal Krishnan"},{"name":"Matthew Mirande","url":"http://busticated.co"}],"gitHead":"4ce93c77b4105c17387d285c4412603d65360a4a","bugs":{"url":"https://github.com/salesforce/secure-filters/issues"},"_id":"secure-filters@1.1.0","_shasum":"e961c2847c2b53556a0d0d90ee83dd1b33da25fd","_from":".","_npmVersion":"4.2.0","_nodeVersion":"7.9.0","_npmUser":{"name":"jstash","email":"jstash@gmail.com"},"dist":{"shasum":"e961c2847c2b53556a0d0d90ee83dd1b33da25fd","tarball":"https://registry.npmjs.org/secure-filters/-/secure-filters-1.1.0.tgz","integrity":"sha512-be/XmInVhbWrlMkJ7fQWwsl0skWmQ9aZiYHvyHMk3i8JxMXmHlR1Q9bIGQKkVnZVyhtonHIi0cLA0TWQ2v6poA==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC5rzkCEqFVuJsmfSD1p2LhaGisl4DMgFjVPAhBcsvWMwIgCgEWlcJEiMGukCyizXeKgxQQTuvtcdVStqkTlIU0G1Q="}]},"maintainers":[{"name":"goinstant","email":"support@goinstant.com"},{"name":"jstash","email":"jstash@gmail.com"}],"_npmOperationalInternal":{"host":"packages-18-east.internal.npmjs.com","tmp":"tmp/secure-filters-1.1.0.tgz_1492550620344_0.407599174650386"}}},"readme":"# secure-filters\n\n`secure-filters` is a collection of Output Sanitization functions (\"filters\")\nto provide protection against [Cross-Site Scripting\n(XSS)](https://owasp.org/index.php/Cross-site_Scripting_%28XSS%29) and other\ninjection attacks.\n\n[![Build Status](https://travis-ci.org/salesforce/secure-filters.png?branch=master)](https://travis-ci.org/salesforce/secure-filters)\n\n![Data Flow Diagram](./images/secure-filters%20data%20flow.png)\n\n### Table of select contents\n\n- [About XSS](#about-xss)\n- [Usage](#usage)\n  - [Installation](#installation) - `npm install --save secure-filters`\n  - [EJS](#with-ejs)\n  - [Normal functions](#as-normal-functions)\n  - [Client-side](#client-side)\n- [Functions](#functions)\n  - [`html(value)`](#htmlvalue) - Sanitizes HTML contexts using entity-encoding.\n  - [`js(value)`](#jsvalue) - Sanitizes JavaScript string contexts using backslash-encoding.\n  - [`jsObj(value)`](#jsobjvalue) - Sanitizes JavaScript literals (numbers, strings,\n    booleans, arrays, and objects) for inclusion in an HTML script context.\n  - [`jsAttr(value)`](#jsattrvalue) - Sanitizes JavaScript string contexts _in an HTML attribute_\n    using a combination of entity- and backslash-encoding.\n  - [`uri(value)`](#urivalue) - Sanitizes URI contexts using percent-encoding.\n  - [`css(value)`](#cssvalue) - Sanitizes CSS contexts using backslash-encoding.\n  - [`style(value)`](#stylevalue) - Sanitizes CSS contexts _in an HTML `style` attribute_\n- [Contributing](#contributing)\n- [Support](#support)\n- [Legal](#legal)\n\n# About XSS\n\nXSS is the [#3 most critical security flaw affecting web\napplications](https://www.owasp.org/index.php/Top_10_2013-A3-Cross-Site_Scripting_%28XSS%29)\nfor 2013, as determined by a broad consensus among\n[OWASP](https://www.owasp.org) members.\n\nTo effectively combat XSS, you must combine Input Validation with Output\nSanitization.  **Using one or the other is not sufficient; you must apply\nboth!**  Also, simple validations like string length aren't as effective; it's\nmuch safer to use _whitelist-based validation_.\n\nThe generally accepted flow in preventing XSS looks like this:\n\n![Data Flow Diagram](./images/secure-filters%20data%20flow.png)\n\nWhichever Input Validation and Output Sanitization modules you end up\nusing, please review the code carefully and apply your own professional\nparanoia. Trust, but verify.\n\n### Input Validation\n\n`secure-filters` doesn't deal with Input Validation, only Ouput Sanitization.\n\nYou can roll your own input validation or you can use an existing module.\nEither way, there are\n[many](https://owasp.org/index.php/Data_Validation)\n[important](https://owasp.org/index.php/XSS_%28Cross_Site_Scripting%29_Prevention_Cheat_Sheet)\nrules to follow.\n\n[This Stack-Overflow\nthread](http://stackoverflow.com/questions/4088723/validation-library-for-node-js)\nlists several input validation options specific to node.js.\n\nOne of those options is node-validator\n([NPM](https://npmjs.org/package/validator),\n[github](https://github.com/chriso/node-validator)).  It provides an impressive\nlist of chainable validators.  Validator also has a 3rd party\n[express-validate](https://github.com/Dream-Web/express-validate) middleware\nmodule for use in the popular [Express](http://expressjs.com/) node.js server.\n\nInput Validation can be specialized to the data format.  For example, the\njsonschema module ([NPM](https://npmjs.org/package/jsonschema),\n[github](https://github.com/tdegrunt/jsonschema)) can be useful for providing\nstrict validation of JSON documents (e.g. bodies in HTTP).\n\n### Output Sanitization\n\nOutput Sanitization (also known as Ouput Filtering) is what `secure-filters` is\nresponsible for.\n\nIn order to properly santize output you need to be sensitive to the _context_\nin which the data is being output. For example, if you want to place text in an\nHTML document, you should HTML-escape the text.\n\nBut what about CSS or JavaScript contexts? You can't use the HTML-escape\nfilter; a different escaping method is necessary. If the filter doesn't match\nthe context, it's possible for browsers to misinterpret the result, which can\nlead to XSS attacks!\n\n`secure-filters` aims to provide the filter functions necessary to do this type\nof context-sensitive sanitization.\n\n### Hybrid Sanitization\n\n\"Sanitization\" is an overloaded term and can be confused with other security\ntechniques.\n\nFor example, if you need to store and sanitize HTML, you'd want to parse,\nvalidate and sanitize that HTML in one hybridized step.  There are tools like\n[Google Caja](http://code.google.com/p/google-caja/) to do HTML sanitization.\nThe [`sanitizer` module](https://github.com/theSmaw/Caja-HTML-Sanitizer)\npackages-up Caja for node.js/CommonJS usage.\n\n# Usage\n\n`secure-filters` can be used with EJS or as normal functions.\n\n## Installation\n\n```sh\n  npm install --save secure-filters\n```\n\n:warning: **CAUTION**: If the `Content-Type` HTTP header for your document, or\nthe `<meta charset=\"\">` tag (or eqivalent) specifies a non-UTF-8 encoding these\nfilters _may not provide adequate protection_! Some browsers can treat some\ncharacters at Unicode code-points `0x00A0` and above as if they were `<` if the\nencoding is not set to UTF-8!\n\n## General Usage\n\n[![Cheat Sheet](./images/secure-filters%20cheat%20sheet.png)](./images/secure-filters%20cheat%20sheet.png)\n\n## With EJS\n\nTo configure EJS, simply wrap your `require('ejs')` call.  This will import the\nfilters using the names pre-defined by this module.\n\n```js\n  var ejs = require('secure-filters').configure(require('ejs'));\n```\n\nThen, within an EJS template:\n\n```html\n  <script>\n    var config = <%-: config |jsObj%>;\n    var userId = parseInt('<%-: userId |js%>',10);\n  </script>\n  <a href=\"/welcome/<%-: userId |uri%>\">Welcome <%-: userName |html%></a>\n  <br>\n  <a href=\"javascript:activate('<%-: userId |jsAttr%>')\">Click here to activate</a>\n```\n\nThere's a handy [cheat sheet](./cheatsheet.md) showing all the filters in EJS syntax.\n\n### Alternative EJS uses.\n\nRather than importing the pre-defined names we've chosen, here are some other\nways to integrate `secure-filters` with EJS.\n\n#### Replacing EJS's default escape\n\nAs of EJS 0.8.4, you can replace the `escape()` function during template\ncompilation.  This allows `<%= %>` to be safer than [the\ndefault](#a-note-about--).\n\n```js\nvar escapeHTML = secureFilters.html;\nvar templateFn = ejs.compile(template, { escape: escapeHTML });\n```\n\n#### One-by-one\n\nIt's possible that the filter names pre-defined by this module interferes with\nexisting filters that you've written. Or, you may wish to import a sub-set of\nthe filters. In which case, you can simply assign properties to the\n`ejs.filters` object.\n\n```js\n  var secureFilters = require('secure-filters');\n  var ejs = require('ejs');\n  ejs.filters.secJS = secureFilters.js;\n```\n\n```html\n  <script>\n    var myStr = \"<%-: myVal | secJS %>\";\n  </script>\n```\n\n#### Parametric\n\nOr, you can namespace using a parametric style, similar to how EJS' pre-defined\n`get:'prop'` filter works:\n\n```js\n  var secureFilters = require('secure-filters');\n  var ejs = require('ejs');\n  ejs.filters.sec = function(val, context) {\n    return secureFilters[context](val);\n  };\n```\n\n```html\n  <script>\n    var myStr = \"<%-: myVal | sec:'js' %>\";\n  </script>\n```\n\n## As Normal Functions\n\nThe filter functions are just regular functions and can be used outside of EJS.\n\n```js\n  var htmlEscape = require('secure-filters').html;\n  var escaped = htmlEscape('\"><script>alert(\\'pwn\\')</script>');\n  assert.equal(escaped,\n    '&quot;&gt;&lt;script&gt;alert&#40;&#39;pwn&#39;&#41;&lt;&#47;script&gt;');\n```\n\n## Client-side\n\nYou can simply include the `lib/secure-filters.js` file itself to get started.\n\n```html\n  <script type=\"text/javascript\" src=\"path/to/secure-filters.js\"></script>\n  <script type=\"text/javascript\">\n    var escaped = secureFilters.html(userInput);\n    //...\n  </script>\n```\n\nWe've also added [AMD module\ndefinition](https://github.com/amdjs/amdjs-api/wiki/AMD) to `secure-filters.js`\nfor use in [Require.js](http://requirejs.org) and other AMD frameworks. We\ndon't pre-define a name, but suggest that you use 'secure-filters'.\n\n# Functions\n\nBy convention in the Contexts below, `USERINPUT` should be replaced with the\noutput of the filter function.\n\n### html(value)\n\nSanitizes output for HTML element and attribute contexts using entity-encoding.\n\nContexts:\n\n```html\n  <p>Hello, <span id=\"name\">USERINPUT</span></p>\n  <div class=\"USERINPUT\"></div>\n  <div class='USERINPUT'></div>\n```\n\n:warning: **CAUTION**: this is not the correct encoding for embedding the contents of\na `<script>` or `<style>` block (plus other blocks that cannot have\nentity-encoded characters).\n\nAny character not matched by `/[\\t\\n\\v\\f\\r ,\\.0-9A-Z_a-z\\-\\u00A0-\\uFFFF]/` is\nreplaced with an HTML entity.  Additionally, characters matched by\n`/[\\x00-\\x08\\x0B\\x0C\\x0E-\\x1F\\x7F-\\x9F]/` are converted to spaces to avoid\nbrowser quirks that interpret these as non-characters.\n\n#### A Note About `<%= %>`\n\nYou might be asking \"Why provide `html(var)`? EJS already does HTML escaping!\".\n\n[Prior to 0.8.5](https://github.com/visionmedia/ejs/blob/master/History.md#085--2013-11-21),\nEJS doesn't escape the `'` (apostrophe) character when using the `<%= %>`\nsyntax.  This can lead to XSS accidents!  Consider the template:\n\n```html\n  <img src='<%= prefs.avatar %>'>\n```\n\nWhen given user input `x' onerror='alert(1)`, the above gets rendered as:\n\n```html\n  <img src='x' onerror='alert(1)'>\n```\n\nWhich will cause the `onerror` javascript to run.  Using this module's filter\nshould prevent this.\n\n```html\n  <img src='<%-: prefs.avatar |html%>'>\n```\n\nWhen given user input `x' onerror='alert(1)`, the above gets rendered as:\n\n```html\n  <img src='x&#39; onerror&#61;&#39;alert&#40;1&#41;'>\n```\n\nWhich will not run the attacking script.\n\n\n### js(value)\n\nSanitizes output for JavaScript _string_ contexts using backslash-encoding.\n\n```html\n  <script>\n    var singleQuote = 'USERINPUT';\n    var doubleQuote = \"USERINPUT\";\n    var anInt = parseInt('USERINPUT', 10);\n    var aFloat = parseFloat('USERINPUT');\n    var aBool = ('USERINPUT' === 'true');\n  </script>\n```\n\n:warning: **CAUTION**: you need to always put quotes around the embedded value; don't\nassume that it's a bare int/float/boolean constant!\n\n:warning: **CAUTION**: this is not the correct encoding for the entire contents of a\n`<script>` block!  You need to sanitize each variable in-turn.\n\nAny character not matched by `/[,\\-\\.0-9A-Z_a-z]/` is escaped as `\\xHH` or\n`\\uHHHH` where `H` is a hexidecimal digit.  The shorter `\\x` form is used for\ncharaters in the 7-bit ASCII range (i.e. code point <= 0x7F).\n\n### json(value)\n\nSanitizes output for a JSON string in an HTML script context.\n\n```html\n  <script>\n    var config = USERINPUT;\n  </script>\n```\n\nThis function escapes certain characters within a JSON string.  Any character\nnot matched by `/[\",\\-\\.0-9:A-Z\\[\\\\\\]_a-z{}]/` is escaped consistent with the\n[`js(value)`](#jsvalue) escaping above. Additionally, the sub-string `]]>` is\nencoded as `\\x5D\\x5D\\x3E` to prevent breaking out of CDATA context.\n\nBecause `<` and `>` are not matched characters, they get encoded as `\\x3C` and\n`\\x3E`, respectively. This prevents breaking out of a surrounding HTML\n`<script>` context.\n\nFor example, with a JSON string like `'{\"username\":\"Albert </script><script>alert(\\\"Pwnerton\\\")\"}'`,\n`json()` gives output:\n\n```html\n  <script>\n    var config = {\"username\":\"\\x3C\\x2Fscript\\x3E\\x3Cscript\\x3Ealert\\x28\\\"Pwnerton\\\"\\x29\"};\n  </script>\n```\n\n### jsObj(value)\n\nSanitizes output for a JavaScript literal in an HTML script context.\n\n```html\n  <script>\n    var config = USERINPUT;\n  </script>\n```\n\nThis function encodes the object with `JSON.stringify()`, then\nescapes using `json()` detailed above.\n\nFor example, with a literal object like `{username:'Albert\n</script><script>alert(\"Pwnerton\")'}`, `jsObj()` gives output:\n\n```html\n  <script>\n    var config = {\"username\":\"\\x3C\\x2Fscript\\x3E\\x3Cscript\\x3Ealert\\x28\\\"Pwnerton\\\"\\x29\"};\n  </script>\n```\n\n#### JSON is not a subset of JavaScript\n\nArticle: [JSON isn't a JavaScript\nSubset](http://timelessrepo.com/json-isnt-a-javascript-subset).\n\nJSON is _almost_ a subset of JavaScript, but for two characters: [`LINE\nSEPARATOR` U+2028](http://www.fileformat.info/info/unicode/char/2028/index.htm)\nand [`PARAGRAPH SEPARATOR`\nU+2029](http://www.fileformat.info/info/unicode/char/2029/index.htm).  These\ntwo characters can't legally appear in JavaScript strings and must be escaped.\nDue to the ambiguity of these and other Unicode whitespace characters,\n`secure-filters` will backslash encode U+2028 as `\\u2028`, U+2029 as `\\u2029`,\netc.\n\n### jsAttr(value)\n\nSanitizes output for embedded HTML scripting attributes using a special\ncombination of backslash- and entity-encoding.\n\n```html\n  <a href=\"javascript:doActivate('USERINPUT')\">click to activate</a>\n  <button onclick=\"display('USERINPUT')\">Click To Display</button>\n```\n\nThe string `<ha>, 'ha', \"ha\"` is escaped to `&lt;ha&gt;, \\&#39;ha\\&#39;,\n\\&quot;ha\\&quot;`. Note the backslashes before the apostrophe and quote\nentities.\n\n### uri(value)\n\nSanitizes output in URI component contexts by using percent-encoding.\n\n```html\n  <a href=\"http://example.com/?this=USERINPUT&that=USERINPUT\">\n  <a href=\"http://example.com/api/v2/user/USERINPUT\">\n```\n\nThe ranges 0-9, A-Z, a-z, plus hypen, dot and underscore (`-._`) are\npreserved. Every other character is converted to UTF-8, then output as %XX\npercent-encoded octets, where X is an uppercase hexidecimal digit.\n\n**Note** that if composing a URL, the entire result should ideally be\nHTML-escaped before insertion into HTML. However, since Percent-encoding is\nalso HTML-safe, it may be sufficient to just URI-encode the untrusted\ncomponents if you know the rest is application-supplied.\n\n### css(value)\n\nSanitizes output in CSS contexts by using backslash encoding.\n\n```html\n  <style type=\"text/css\">\n    #user-USERINPUT {\n      background-color: #USERINPUT;\n    }\n  </style>\n```\n\n:warning: **CAUTION** this is not the correct filter for a `style=\"\"` attribute; use\nthe [`style(value)`](#stylevalue) filter instead!\n\n:warning: **CAUTION** even though this module prevents breaking out of CSS\ncontext, it is still somewhat risky to allow user-controlled input into CSS and\n`<style>` blocks. Be sure to combine CSS escaping with _whitelist-based_ input\nsanitization! Here's a small sampling of what's possible:\n\n- https://www.computerworld.com/s/article/9221043/Opera_denies_refusing_to_patch_critical_vulnerability\n- http://html5sec.org/#43 - note the modern browser versions!\n\n\nThe ranges a-z, A-Z, 0-9 plus Unicode U+10000 and higher are preserved.  All\nother characters are encoded as `\\h `, where `h` is one one or more lowercase\nhexadecimal digits, including the trailing space.\n\nConfusingly, CSS allows `NO-BREAK SPACE` U+00A0 to be used in an identifier.\nBecause of this confusion, it's possible browsers treat it as whitespace, and\nso `secure-filters` escapes it.\n\nSince [the behaviour of NUL in CSS2.1 is\nundefined](http://www.w3.org/TR/CSS21/syndata.html#characters), it is replaced\nwith `\\fffd `, `REPLACEMENT CHARACTER` U+FFFD.\n\nFor example, the string `<wow>` becomes `\\3c wow\\3e ` (note the trailing space).\n\n### style(value)\n\nEncodes values for safe embedding in HTML style attribute context.\n\n**USAGE**: all instances of `USERINPUT` should be sanitized by this function\n\n```html\n  <div style=\"background-color: #USERINPUT;\"></div>\n```\n\n:warning: **CAUTION** even though this module prevents breaking out of style-attribute\ncontext, it is still somewhat risky to allow user-controlled input (see caveats\non [css](#cssvalue) above).  Be sure to combine with _whitelist-based_ input\nsanitization!\n\nEncodes the value first as in the `css()` filter, then HTML entity-encodes the result.\n\nFor example, the string `<wow>` becomes `&#92;3c wow&#92;3e `.\n\n# Contributing\n\nPlease see the [Contribution Guide](./contributing.md).\n\n# Support\n\nSupport is provided via [github issues](https://github.com/salesforce/secure-filters/issues).\n\nFor responsible disclosures, email [Salesforce Security](mailto:security@salesforce.com).\n\n# Changelog\n\n#### 1.1.0\n\nThis release changes the behavior of secure-filters, but should be\nbackwards-compatible with 1.0.5.\n\n- The `js`, `jsObj` and `jsAttr` filter now use a strict allow-list for\n  characters in strings.  This is safer, but does increase the size of these\n  strings slightly.  Compliant JSON and JavaScript parsers will not be affected\n  negatively by this change.\n- The example for `jsAttr` was incorrect.  It previously stated that `<ha>,\n  'ha', \"ha\"` was escaped to `&lt;ha&gt;, \\&#39;ha\\&#39;, \\&quot;ha\\&quot;`\n\n#### 1.0.5\n\n- Vastly improved documentation and illustrations\n\n#### 1.0.4\n\n- Initial public release\n\n# Legal\n\n&copy; 2014 salesforce.com\n\nLicensed under the BSD 3-clause license.\n","maintainers":[{"email":"clint@ruoho.org","name":"ruoho"},{"email":"marat+npm@salesforce.com","name":"maratto"},{"email":"jstash@gmail.com","name":"jstash"},{"email":"support@goinstant.com","name":"goinstant"}],"time":{"modified":"2022-06-26T17:13:52.316Z","created":"2013-11-21T23:29:18.986Z","1.0.3":"2013-11-21T23:29:25.208Z","1.0.4":"2013-11-22T01:38:59.396Z","1.0.5":"2013-12-18T19:45:13.911Z","1.1.0":"2017-04-18T21:23:42.613Z"},"author":{"name":"Salesforce.com, Inc."},"repository":{"type":"git","url":"git+ssh://git@github.com/salesforce/secure-filters.git"},"users":{"rnsloan":true,"overcast":true,"rocket0191":true,"tribou":true},"homepage":"http://salesforce.github.io/secure-filters/","keywords":["security","xss","ejs","escape","encode"],"bugs":{"url":"https://github.com/salesforce/secure-filters/issues"},"license":"BSD-3-Clause","readmeFilename":"README.md","contributors":[{"name":"Jeremy Stashewsky","email":"jstashewsky@salesforce.com"},{"name":"Amal Krishnan"},{"name":"Matthew Mirande","url":"http://busticated.co"}]}