Closed Bug 2020700 Opened 7 months ago Closed 7 months ago

setHTML does not keep attributes which are allowed by the sanitizer

Categories

(Core :: DOM: Security, defect)

Firefox 148
defect

Tracking

()

RESOLVED INVALID

People

(Reporter: bomsy, Unassigned)

Details

Attachments

(1 file)

Attached file testpage.html —

Setting the attributes property seems to have no effect. The class attributes are not preserved in the output

const unsafeHTML = `
	<span class="foo">
  	    <span class="bar"></span>
        </span>
  `;
  
const sanitizer = new Sanitizer({ elements: ["span"], attributes: ["class"]});
target.setHTML(unsafeHTML, sanitizer);
console.log(target.innerHTML)

Actual Output

 <span>
    <span></span>
 </span>

Expected Output

 <span class="foo">
    <span class="bar"></span>
 </span>

Note: A test page is also attached

Blocks: 2015445

The second argument of setHTML is a dictionary, you need to use the key "sanitizer".

This works:

target.setHTML(unsafeHTML, {sanitizer});
No longer blocks: 2015445
Status: NEW → RESOLVED
Closed: 7 months ago
Resolution: --- → INVALID
No longer blocks: sanitizer-api
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: