Can OpenLayers safely render GPX/GeoJSON/KML from user-input?

Viewed 51

I'm building a mapping application in which I would like to allow users to share their own routes, tracks, and points with others (sourced from their own GPX/GeoJSON/KML files).

I'm aware that rendering pop-up controls by setting element innerHTML to unsanitized content would present a potential injection vulnerability.

What I'm wondering about is the safety (or lack there-of) of sourcing and rendering geometry from untrusted content. Does OpenLayers do any validation or cleaning that can allow it to render untrusted geometries safely?

0 Answers
Related