# How to bind a javascript href and bypass XSS unsafe protection?

**URL:** <https://discuss.emberjs.com/t/how-to-bind-a-javascript-href-and-bypass-xss-unsafe-protection/7494>\
**Category:** Uncategorized\
**Created:** [March 11, 2015, 10:00am UTC](https://discuss.emberjs.com/t/how-to-bind-a-javascript-href-and-bypass-xss-unsafe-protection/7494 "2015-03-11T10:00:49Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![andruby](https://sea1.discourse-cdn.com/flex019/user_avatar/discuss.emberjs.com/andruby/32/15376_2.png) [@andruby](https://discuss.emberjs.com/u/andruby)\
**Post date:** [March 11, 2015, 10:00am UTC](https://discuss.emberjs.com/t/how-to-bind-a-javascript-href-and-bypass-xss-unsafe-protection/7494/1 "2015-03-11T10:00:49Z")

</div>

Hi,

I need to bind a javascript payload to an `<a href={{bookmarklet_url}}>` element. The bookmarklet\_url is generated through a computed property and is safe from user inputs.

Ember added protection against this type of XSS in 1.9.1 which add “unsafe:” to the href. We were able bypass the protection with `{{unbound bookmarklet_url}}`.

We’ve moved to Ember v1.11.0 beta’s and our workaround no longer works. How can I bypass the XSS protection?

Thanks, Andrew

---

<div class="post-metadata">

**Author:** ![Balu](https://sea1.discourse-cdn.com/flex019/user_avatar/discuss.emberjs.com/balu/32/10401_2.png) [@Balu](https://discuss.emberjs.com/u/Balu)\
**Post date:** [March 29, 2016, 8:03am UTC](https://discuss.emberjs.com/t/how-to-bind-a-javascript-href-and-bypass-xss-unsafe-protection/7494/2 "2016-03-29T08:03:34Z")

</div>

Hi, In Ember 1.11.0 version the Ember team has introduced bound attribute syntax feature. So we don’t need to escape/bypass any of the inputs. Ember does this for you by default.

For better understanding please refer to: [Ember.js 1.11.0 and 1.12 Beta Released](http://emberjs.com/blog/2015/03/27/ember-1-11-0-released.html)
