--

Where should something like ap.use(xss()) go? Mine does not appear to be working. It is before my routes. Not sure what should happen but I was able to pass <script>alert"gotcha')</script> and it got stored in the database.

--

--

gravity well (Rob Tomlin)
gravity well (Rob Tomlin)

Written by gravity well (Rob Tomlin)

Software Engineering Manager. Explorer, learner, teacher, and more

No responses yet