3 ms·
Friendly reminder that inline CSS is unsafe and should be avoided. https://stackoverflow.com/questions/41925390 https://stackoverflow.com/questions/41925390
by ximm 2y ago
Friendly reminder that inline CSS is unsafe and should be avoided. https://stackoverflow.com/questions/41925390 https://stackoverflow.com/questions/41925390
- grardb 2y agoJust to make sure I'm not missing anything: All of that essentially only applies to user/untrusted input, right? i.e. if I have a static website with inline CSS (or JS), there's no security concern. In that case, I'm not sure I'd consider inline CSS "unsafe." But it's interesting to see how CSS can be exploited in the same way that JS can be.
- audiodude 2y agoWait WTF, `javascript:` URLs are acceptable in the CSS `url` property?? From the SO post: > url('javascript: eval(evil)');