Giving the artefact access to the query string sounds ok. Easiest thing would be to use Ruby to inject it into the untrusted html document. Maybe as a meta tag or something.
3 Likes
Giving the artefact access to the query string sounds ok. Easiest thing would be to use Ruby to inject it into the untrusted html document. Maybe as a meta tag or something.