Skip to content
This repository has been archived by the owner on Feb 8, 2023. It is now read-only.

Sanitizer: drop all CSS #13

Open
twm opened this issue Jul 4, 2020 · 0 comments
Open

Sanitizer: drop all CSS #13

twm opened this issue Jul 4, 2020 · 0 comments
Labels
bug Something isn't working

Comments

@twm
Copy link
Owner

twm commented Jul 4, 2020

The current CSS sanitizing regime has a lot of issues:

Most importantly though, it doesn't parse CSS. It's doubtful that the implementation is correct, and therefore, secure. For now, the safest thing to do is to drop all CSS.

@twm twm added the bug Something isn't working label Jul 4, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant