diff --git a/src/controllers/index.js b/src/controllers/index.js index dbd41d360c..aa3570b829 100644 --- a/src/controllers/index.js +++ b/src/controllers/index.js @@ -391,7 +391,7 @@ Controllers.manifest = function (req, res) { Controllers.outgoing = function (req, res, next) { var url = req.query.url || ''; - if (!url) { + if (!url || url.startsWith('javascript:')) { return next(); }