A RetroSearch Logo

Home - News ( United States | United Kingdom | Italy | Germany ) - Football scores

Search Query:

Showing content from https://www.mediawiki.org/wiki/Special:MyLanguage/Manual:$wgUseXssLanguage below:

Manual:$wgUseXssLanguage - MediaWiki

Whether to enable the x-xss language code, used to make checking for XSS issues more convenient.

When this feature is enabled, the language code can be selected via the ?uselang=x-xss URL parameter. In this fake language, every interface message becomes a simulated cross-site scripting attack, trying to run alert("message-key") JavaScript code; this simulates an attacker who can change individual messages (e.g. an administrator who can edit the MediaWiki namespace ). This feature does not affect parser output. If any alert is shown in the browser, then the corresponding message was not escaped correctly; either the code using the message needs to be fixed, or the message key should be added to $wgRawHtmlMessages .

If you want this to also apply to messages using ->inContentLanguage(), you will need to set $wgLanguageCode = 'x-xss';.

This feature should never be enabled on a production wiki, but it can be very useful for development.


RetroSearch is an open source project built by @garambo | Open a GitHub Issue

Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo

HTML: 3.2 | Encoding: UTF-8 | Version: 0.7.4