QuestionQ9

Adobe Experience Manager Sites

An Adobe Commerce developer must pass JSON data to a JavaScript component while considering XSS-prevention strategies.

Which two options should the developer use?

Choose two
Explanation

Adobe Commerce permits JSON to be emitted without sanitization when it is used as JSON within a <script> tag. JSON placed in an HTML attribute must be escaped with escapeHtmlAttr so attribute-delimiting characters cannot break out into executable markup. Applying escapeHtmlAttr to JSON in a script context is not the prescribed context-specific method.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!