In a phtml, you added script tag and defined couple of js variables as below:Now to protect it from XSS attacks, which two methods allow you to keep the php variable output XSS-safe?Choose 2
In a phtml, you added script tag and defined couple of js variables as below:Now to protect it from XSS attacks, which two methods allow you to keep the php variable output XSS-safe?Choose 2
I vaguely recall a practice question where we had to choose between escaping methods, and I think both escapeJs and escapeHtmlAttr were mentioned as important.
I've got this! The key is to use the appropriate Magento helper methods to escape the output and prevent XSS attacks. I'll go with escapeJs() and escapeHtmlAttr().
Okay, let me think this through. I need to use methods that can safely output PHP variables in a JavaScript context. I think escapeJs() and escapeHtmlAttr() are the way to go.
Hmm, I'm not entirely sure about this one. I remember learning that SteelCentral Portal can be deployed in different ways, but I'm having trouble recalling the specifics. I'll have to think this through carefully.
I'm not sure about the answer. Can someone explain why D) $block->escapeHtmlAttr($myUrl) is not one of the methods to keep the php variable output XSS-safe?
Marshall
7 months agoShanda
7 months agoMargret
7 months agoKristel
7 months agoLong
7 months agoRodolfo
8 months agoHector
8 months agoDannie
8 months agoPaola
8 months agoHester
8 months agoYuette
8 months agoSuzan
8 months agoEzekiel
8 months agoNadine
9 months agoBrent
9 months agoAlison
1 year agoRenea
1 year agoKenda
1 year agoGlenn
12 months agoAmie
12 months agoFrancene
12 months agoMarvel
1 year agoReyes
1 year agoCary
12 months agoClement
12 months agoRachael
12 months agoMelodie
1 year agoVivienne
1 year agoMaryann
1 year agoBernadine
1 year agoHannah
1 year agoLinwood
1 year agoAllene
1 year agoDean
1 year agoLashaun
1 year agoPura
1 year agoEdison
1 year agoGlenna
1 year agoJamey
1 year agoGracia
1 year ago