In a phtml, you added script tag and defined couple of js variables as below:Now to protect it from XSS attacks, which two methods allow you to keep the php variable output XSS-safe?Choose 2
I vaguely recall a practice question where we had to choose between escaping methods, and I think both escapeJs and escapeHtmlAttr were mentioned as important.
I've got this! The key is to use the appropriate Magento helper methods to escape the output and prevent XSS attacks. I'll go with escapeJs() and escapeHtmlAttr().
Okay, let me think this through. I need to use methods that can safely output PHP variables in a JavaScript context. I think escapeJs() and escapeHtmlAttr() are the way to go.
Hmm, I'm not entirely sure about this one. I remember learning that SteelCentral Portal can be deployed in different ways, but I'm having trouble recalling the specifics. I'll have to think this through carefully.
I'm not sure about the answer. Can someone explain why D) $block->escapeHtmlAttr($myUrl) is not one of the methods to keep the php variable output XSS-safe?
Marshall
3 months agoShanda
3 months agoMargret
3 months agoKristel
4 months agoLong
4 months agoRodolfo
4 months agoHector
4 months agoDannie
4 months agoPaola
5 months agoHester
5 months agoYuette
5 months agoSuzan
5 months agoEzekiel
5 months agoNadine
5 months agoBrent
5 months agoAlison
9 months agoRenea
9 months agoKenda
9 months agoGlenn
8 months agoAmie
8 months agoFrancene
8 months agoMarvel
9 months agoReyes
10 months agoCary
8 months agoClement
8 months agoRachael
8 months agoMelodie
8 months agoVivienne
9 months agoMaryann
9 months agoBernadine
9 months agoHannah
9 months agoLinwood
10 months agoAllene
10 months agoDean
10 months agoLashaun
10 months agoPura
11 months agoEdison
9 months agoGlenna
9 months agoJamey
11 months agoGracia
11 months ago