3 ms·
This is for sanitizing content generated client-side which might not touch server at all. You can create HTML and put it into the DOM on the client
by masa331 5y ago
This is for sanitizing content generated client-side which might not touch server at all. You can create HTML and put it into the DOM on the client
- silon42 5y agoIf you are generating, you should have a whitelist of safe html/css.. Apart from performance this smells of not using a whitelist mechanism (I hope this is not the case).
- masa331 5y agoWhat? Whitelisting is one technique which you can use in sanitizing content generated from unknown sources. If you need to generated such content then it's a probably a special feature of your software and no smell
- kapep 5y ago> this smells of not using a whitelist mechanism What makes you think that? I just skimmed the draft and it seems to use a sensible whitelist as default. Developers can allow or deny additional elements/attributes as they like.