vendor/assets/javascripts/name.html in easyxdm-rails-0.0.7 vs vendor/assets/javascripts/name.html in easyxdm-rails-0.0.8

- old
+ new

@@ -22,9 +22,12 @@ channel = hash; } else { channel = hash.substring(0, indexOf); url = decodeURIComponent(hash.substring(indexOf + 1)); + if (url && !/^https?:\/\//.test(url)) { + throw new Error('Invalid url'); + } } switch (location.hash.substring(2, 3)) { case "2": // NameTransport local window.parent.parent.easyXDM.Fn.get(channel)(window.name);