https://systw.net/note/archives/1221
DOM XSS