diff --git a/app/routes/contributions.js b/app/routes/contributions.js index 7f68170b9..caba798e4 100644 --- a/app/routes/contributions.js +++ b/app/routes/contributions.js @@ -29,16 +29,15 @@ function ContributionsHandler(db) { /*jslint evil: true */ // Insecure use of eval() to parse inputs - const preTax = eval(req.body.preTax); - const afterTax = eval(req.body.afterTax); - const roth = eval(req.body.roth); + // const preTax = eval(req.body.preTax); + // const afterTax = eval(req.body.afterTax); + // const roth = eval(req.body.roth); - /* //Fix for A1 -1 SSJS Injection attacks - uses alternate method to eval const preTax = parseInt(req.body.preTax); const afterTax = parseInt(req.body.afterTax); const roth = parseInt(req.body.roth); - */ + const { userId } = req.session;