Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and
privacy statement. We’ll occasionally send you account related emails.
Already on GitHub?
to your account
If used incorrectly, it can increase the chance of adding xss vulnerabilities. So probably best to remove it from the api
The text was updated successfully, but these errors were encountered:
You should also investigate places where html strings are passed as parameters eg deprecate the Dropdown constructor that uses it.
Modules that currently seem to use Selection::html -
Several tests also use the html getter. Maybe we can get away with just deprecating the setter ?
Do we also want to deprecate hx.parseHTML for the same reason ?
Yes, I think so
Successfully merging a pull request may close this issue.