Closed
Bug 2020700
Opened 7 months ago
Closed 7 months ago
setHTML does not keep attributes which are allowed by the sanitizer
Categories
(Core :: DOM: Security, defect)
Tracking
()
RESOLVED
INVALID
People
(Reporter: bomsy, Unassigned)
Details
Attachments
(1 file)
|
553 bytes,
text/html
|
Details |
Setting the attributes property seems to have no effect. The class attributes are not preserved in the output
const unsafeHTML = `
<span class="foo">
<span class="bar"></span>
</span>
`;
const sanitizer = new Sanitizer({ elements: ["span"], attributes: ["class"]});
target.setHTML(unsafeHTML, sanitizer);
console.log(target.innerHTML)
Actual Output
<span>
<span></span>
</span>
Expected Output
<span class="foo">
<span class="bar"></span>
</span>
Note: A test page is also attached
Comment 1•7 months ago
|
||
The second argument of setHTML is a dictionary, you need to use the key "sanitizer".
This works:
target.setHTML(unsafeHTML, {sanitizer});
Updated•7 months ago
|
No longer blocks: sanitizer-api
You need to log in
before you can comment on or make changes to this bug.
Description
•