Skip to content

allowing style attribute is not safe #32

@espretto

Description

@espretto

CSS can be harmful and must be sanitized w/ e.g. cssfilter. It is not a safe default setting to allow the style attribute.

allowedAttrs: ['style'],

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions