Closed Bug 2003895 Opened 9 months ago Closed 9 months ago

Ship the Sanitizer API

Categories

(Core :: DOM: Security, task)

task

Tracking

()

RESOLVED FIXED
148 Branch
Tracking Status
relnote-firefox --- 148+
firefox148 --- fixed

People

(Reporter: tschuster, Assigned: tschuster)

References

(Blocks 1 open bug)

Details

(Keywords: dev-doc-complete)

Attachments

(1 file)

No description provided.
Summary: Enable the Sanitizer API in early-Beta and ealier → Ship the Sanitizer API
Assignee: nobody → tschuster
Status: NEW → RESOLVED
Closed: 9 months ago
Resolution: --- → FIXED
Target Milestone: --- → 148 Branch

Tom, could you consider nominating this for a release note? (Process info)

Flags: needinfo?(tschuster)

Release Note Request (optional, but appreciated)
[Why is this notable]: New API
[Affects Firefox for Android]: zes
[Suggested wording]: Firefox now supports the Element.setHTML() and Document.parseHTML() functions, to safely set or parse HTML with a built-in sanitizer, which can help prevent Cross-Site Scripting vulnerabilities. We also support the Sanitizer() constructor to configure the HTML sanitization.
[Links (documentation, blog post, etc)]: https://developer.mozilla.org/en-US/docs/Web/API/Sanitizer

relnote-firefox: --- → ?
Flags: needinfo?(tschuster)

Thanks, added to the Fx148 nightly release notes, please allow 30 minutes for the site to update.
Keeping the relnote-firefox flag as ? to keep it on the radar for inclusion in the final Fx148 release notes.

QA Whiteboard: [qa-triage-done-c149/b148]

Added to the final Fx148 release notes

Fx 148 shipped but dev-doc-needed is still on this bug. Notably, Document.parseHTML is still listed as Nightly-only, despite it being available by default in 148.

Is it just this BCD entry or is there more that is left to update? When completed please change dev-doc-needed to dev-doc-complete.

FF148 MDN docs work for this can be tracked in https://github.com/mdn/content/issues/42755

FYI, most of the compatibility data and release note done by others. All I've done is added more information on the default configuration (courtesy TomS) and fixed up the ambiguity in the docs that this was limited to only removing XSS-unsafe stuff.
I've marked as dev-doc-complete, but that doc is still going through review.

You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: