-
-
Notifications
You must be signed in to change notification settings - Fork 142
Open
Labels
allowlistissues related to what tags or attributes are allowedissues related to what tags or attributes are allowed
Milestone
Description
DOMPurify appears to be well-maintained and has an up-to-date allowlist. Explore using those allowlists instead of the HTML5lib-derived lists currently used by Loofah.
- determine how well whitelists match up to the currently-used-set
- determine how big the diff is
- look at using
IS_ALLOWED_URIto allowlist protocols - make sure to include the DOMPurify license in any machine-generated file
- consider making a separate gem for Loofah's allowlist and inject it into Loofah by default
- ... and then document how anybody else can modify or inject their own allowlists, which should address a lot of open issues (see the
allowlistlabel) - ... and deprecate
Whitelistin preference toAllowlist, exploring how to do so without totally breaking monkeypatches people may have made to Loofah's allowlists.
dotneet and joemsak
Metadata
Metadata
Assignees
Labels
allowlistissues related to what tags or attributes are allowedissues related to what tags or attributes are allowed
Projects
Status
No status