Skip to content

Conversation

@Rokt33r
Copy link
Member

@Rokt33r Rokt33r commented Mar 14, 2018

No description provided.

@Rokt33r Rokt33r merged commit 826a67b into master Mar 14, 2018
@Rokt33r Rokt33r deleted the allow-more branch March 14, 2018 04:09
],
allowedAttributes: {
'*': [
'style',
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

After taking some time to reflect, I feel in my heart that this is very tempting but a bad idea. Please see #1672 (comment) where I try to explain that it doesn't matter that you cannot do a known xss. style is a known problematic attribute, and a potent target for new exploits.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants