Updated Date: 07/07/2026
Removing JavaScript event listeners from parameters
Before you can remove JavaScript event listeners from parameters, Application Layer Encryption must be enabled on the URL or view.
You can remove JavaScript event listeners from parameters to protect sensitive data in parameters from being obtained by potential attackers.
Note: Some web applications add non-malicious event listeners that improve functionality. If you choose to activate removal of event listeners on parameters, this will remove all event listeners, including non-malicious ones added by the web application. Take this into account before deciding to activate removal of event listeners.
-
On the Main tab, click Security > Fraud Protection Service > Anti-Fraud Profiles.
The Anti-Fraud Profiles screen opens.
-
From the list of profiles, select the relevant profile.
The Anti-Fraud Profile Properties screen opens.
-
In the Anti-Fraud Configuration area, click URL List.
The URL List opens.
-
Select the URL or view on which you want to remove JavaScript event listeners.
The URL Properties (or View Properties) screen opens.
-
In the URL Configuration (or View Configuration) area, select Application Layer Encryption.
The Application Layer Encryption settings are displayed.
-
Click Advanced and select the Enabled check box for the Remove Event Listeners setting.
-
In the URL Configuration (or View Configuration) area, select Parameters.
The Parameters list is displayed.
-
Click the Add button.
The Parameter Settings screen opens.
-
In the Parameter Name field, choose one of the following types for the parameter name:
- Explicit: Assign a specific parameter name.
- Wildcard: Assign a wildcard expression for the parameter name. Any parameter name that matches the wildcard expression is considered legal and receives protection. For example, typing the wildcard expression
*specifies that any parameter name is allowed.
-
In the Application Layer Encryption section, select the Obfuscate check box or the Substitute Value check box.
Note: If you assign the Substitute Value attribute to a password parameter, the web browser’s auto-complete feature for passwords does not work on this parameter.
-
Click Create.
The parameter settings are saved and the URL Properties (or View Properties) screen appears.
-
Repeat steps 8-11 for every parameter on which you want to remove JavaScript event listeners.
-
Click Save in the URL/View Properties screen.
The configuration settings for the URL or view are saved.