45 lines
1.4 KiB
JavaScript
45 lines
1.4 KiB
JavaScript
$(document).ready(function () {
|
|
$("#postComment").on("click", function () {
|
|
var commentInput = $("#commentInput").val();
|
|
$.ajax({
|
|
type: 'POST',
|
|
url: 'CrossSiteScripting/stored-xss',
|
|
data: JSON.stringify({text: commentInput}),
|
|
contentType: "application/json",
|
|
dataType: 'json'
|
|
}).then(
|
|
function () {
|
|
getChallenges();
|
|
$("#commentInput").val('');
|
|
}
|
|
)
|
|
})
|
|
|
|
var html = '<li class="comment">' +
|
|
'<div class="pull-left">' +
|
|
'<img class="avatar" src="images/avatar1.png" alt="avatar"/>' +
|
|
'</div>' +
|
|
'<div class="comment-body">' +
|
|
'<div class="comment-heading">' +
|
|
'<h4 class="user">USER</h4>' +
|
|
'<h5 class="time">DATETIME</h5>' +
|
|
'</div>' +
|
|
'<p>COMMENT</p>' +
|
|
'</div>' +
|
|
'</li>';
|
|
|
|
getChallenges();
|
|
|
|
function getChallenges() {
|
|
$("#list").empty();
|
|
$.get('CrossSiteScripting/stored-xss', function (result, status) {
|
|
for (var i = 0; i < result.length; i++) {
|
|
var comment = html.replace('USER', result[i].user);
|
|
comment = comment.replace('DATETIME', result[i].dateTime);
|
|
comment = comment.replace('COMMENT', result[i].text);
|
|
$("#list").append(comment);
|
|
}
|
|
|
|
});
|
|
}
|
|
}) |