Improved unscanned POST blocking.

This commit is contained in:
hackademix 2019-03-20 23:34:32 +01:00
parent cab9d0ea74
commit 169d5f085a
1 changed files with 2 additions and 2 deletions

View File

@ -246,8 +246,8 @@ var XSS = (() => {
request.requestBody && request.requestBody.formData &&
ic.checkPost(request.requestBody.formData, skipParams)
: XSS.xssBlockUnscannedPOST &&
request.documentUrl && // exclude non-document POSTs, such as url bar searches
ns.requestCan(request, "script") && _("UnscannedXPost")
(request.originUrl || request.documentUrl) && // exclude non-document POSTs, such as url bar searches
ns.requestCan(request, "script") && ("\n" + _("UnscannedXPost"))
);
let protectName = ic.nameAssignment;