Skip to content

Conversation

@Lubrsi
Copy link
Contributor

@Lubrsi Lubrsi commented Oct 29, 2025

Prevents observably calling Trusted Types, which can run arbitrary JS, cause crashes due to use of MUST and allow arbitrary JS to modify internal elements.

@tete17
Copy link
Contributor

tete17 commented Oct 30, 2025

I wonder if the test brakes around iframes have anything to do here?

@Lubrsi Lubrsi force-pushed the do-not-invoke-trusted-types-when-not-needed branch from 09e29f2 to 2e27e17 Compare October 31, 2025 12:37
@Lubrsi Lubrsi marked this pull request as ready for review October 31, 2025 12:37
Copy link
Member

@AtkinsSJ AtkinsSJ left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only nits. Otherwise this looks good, and I appreciate renaming some of these _for_bindings()! I've never been sure which set_attribute() method I'm supposed to be using. 😅

Prevents observably calling Trusted Types, which can run arbitrary JS,
cause crashes due to use of MUST and allow arbitrary JS to modify
internal elements.
@Lubrsi Lubrsi force-pushed the do-not-invoke-trusted-types-when-not-needed branch from 2e27e17 to 1b6e161 Compare November 4, 2025 15:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants