Join GitHub today
GitHub is home to over 40 million developers working together to host and review code, manage projects, and build software together.Sign up
allow titles for abbreviation elements #184
I double checked this allow rule still prevents common XSS attack vectors. Like closing the title attribute and inserting an onload, or closing the element entirely and injecting a new element like
But now titles such as "This is a title: with a sub tile" render as expected.