Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

What about data URLs? #8

Closed
mozfreddyb opened this issue Jun 5, 2020 · 2 comments
Closed

What about data URLs? #8

mozfreddyb opened this issue Jun 5, 2020 · 2 comments

Comments

@mozfreddyb
Copy link
Collaborator

DOMPurify allows for audio,video,img,source,image,track only. Browsers are blocking top-level navigations by now..Is that enough?

@mozfreddyb mozfreddyb added question sanitizer-algorithm issue with the algorithm labels Jun 5, 2020
@cure53
Copy link
Collaborator

cure53 commented Jul 27, 2020

They should pretty much be generally considered as safe, we are a bit paranoid in DOMPurify.

@mozfreddyb
Copy link
Collaborator Author

Let's use #26 for this one.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants