mirror of
https://github.com/elicpeter/nyx.git
synced 2026-06-09 19:45:13 +02:00
10 lines
264 B
JavaScript
10 lines
264 B
JavaScript
|
|
// Unsafe: Express `res.setHeader` receives a value built from req.query.
|
||
|
|
// HEADER_INJECTION fires on the value argument.
|
||
|
|
function handler(req, res) {
|
||
|
|
const lang = req.query.lang;
|
||
|
|
res.setHeader('X-Lang', lang);
|
||
|
|
res.end();
|
||
|
|
}
|
||
|
|
|
||
|
|
module.exports = handler;
|