https://github.com/LukeAskew/Front-End-Standards/blob/master/JavaScript/Security.md -- the hash is just a string, it never gets evaled or inserted in dom. Does that allow xss?
https://github.com/LukeAskew/Front-End-Standards/blob/master/JavaScript/Security.md
-- the hash is just a string, it never gets evaled or inserted in dom. Does that allow xss?