summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorRobin Berjon <robin@berjon.com>2012-10-25 15:06:06 +0200
committerRobert Newson <rnewson@apache.org>2012-10-25 14:14:24 +0100
commitb99ec792110d0f06a42e38fb6f0208d3b6b3bcc7 (patch)
tree7a9272ce66f6bb314e1803cad3780376ca619a87
parent07a6af222247d34c41ee8eabec9822c26a407ff8 (diff)
downloadcouchdb-b99ec792110d0f06a42e38fb6f0208d3b6b3bcc7.tar.gz
disallow https for remote loading as well
-rw-r--r--share/www/script/couch_test_runner.js1
1 files changed, 1 insertions, 0 deletions
diff --git a/share/www/script/couch_test_runner.js b/share/www/script/couch_test_runner.js
index d1a53e91e..b09aeab62 100644
--- a/share/www/script/couch_test_runner.js
+++ b/share/www/script/couch_test_runner.js
@@ -16,6 +16,7 @@
function loadScript(url) {
// disallow loading remote URLs
if((url.substr(0, 7) == "http://")
+ || (url.substr(0, 8) == "https://")
|| (url.substr(0, 2) == "//")
|| (url.substr(0, 5) == "data:")
|| (url.substr(0, 11) == "javascript:")) {