In a phtml, you added script tag and defined couple of js variables as below:Now to protect it from XSS attacks, which two methods allow you to keep the php variable output XSS-safe?Choose 2
I vaguely recall a practice question where we had to choose between escaping methods, and I think both escapeJs and escapeHtmlAttr were mentioned as important.
I've got this! The key is to use the appropriate Magento helper methods to escape the output and prevent XSS attacks. I'll go with escapeJs() and escapeHtmlAttr().
Okay, let me think this through. I need to use methods that can safely output PHP variables in a JavaScript context. I think escapeJs() and escapeHtmlAttr() are the way to go.
Hmm, I'm not entirely sure about this one. I remember learning that SteelCentral Portal can be deployed in different ways, but I'm having trouble recalling the specifics. I'll have to think this through carefully.
I'm not sure about the answer. Can someone explain why D) $block->escapeHtmlAttr($myUrl) is not one of the methods to keep the php variable output XSS-safe?
Marshall
4 months agoShanda
5 months agoMargret
5 months agoKristel
5 months agoLong
5 months agoRodolfo
6 months agoHector
6 months agoDannie
6 months agoPaola
6 months agoHester
6 months agoYuette
6 months agoSuzan
6 months agoEzekiel
6 months agoNadine
6 months agoBrent
7 months agoAlison
11 months agoRenea
11 months agoKenda
11 months agoGlenn
9 months agoAmie
10 months agoFrancene
10 months agoMarvel
10 months agoReyes
11 months agoCary
10 months agoClement
10 months agoRachael
10 months agoMelodie
10 months agoVivienne
10 months agoMaryann
10 months agoBernadine
10 months agoHannah
11 months agoLinwood
12 months agoAllene
12 months agoDean
12 months agoLashaun
12 months agoPura
1 year agoEdison
11 months agoGlenna
11 months agoJamey
1 year agoGracia
1 year ago