Issues
- 4
Handling of omitted vs empty lists
#268 opened by evilpie - 5
- 0
- 0
Skip unnecessary steps in sanitize core algorithm
#274 opened by evilpie - 3
- 0
- 2
Safe sanitizer default
#228 opened by annevk - 1
Solving safe/unsafe defaults
#233 opened by annevk - 1
- 5
Duplication of global attributes as element specific attributes in default config
#271 opened by evilpie - 6
- 7
Is `get()` not explicit enough?
#258 opened by mozfreddyb - 3
- 10
Spec bugs / clarifications
#249 opened by otherdaniel - 0
Sanitizer should not be exposed to Worker context
#256 opened by evilpie - 24
How to handle event handler attributes
#226 opened by lukewarlow - 5
Sanitizer vs ARIA
#245 opened by otherdaniel - 3
Renaming of the resources folder breaks Symfony CI
#251 opened by Stoakes - 0
javascript: URL handling is incorrect
#246 opened by annevk - 2
Update whatwg/html's editor checklist to check whether new elements and attributes need to be added to the allow lists
#206 opened by mbrodesser-Igalia - 6
- 6
- 9
otherMarkup
#240 opened by otherdaniel - 7
extend() static and instance method for Sanitizer
#229 opened by annevk - 11
Renaming methods to prefix them with `add` make it clear there is a modification of the instance
#238 opened by mozfreddyb - 12
Bug in assert_node_equals hides test failures
#202 opened by evilpie - 1
Compatibility with new `setHTMLUnsafe` and `parseHTMLUnsafe` methods/Declarative Shadow Roots
#236 opened by shgysk8zer0 - 1
Chainable modifiers?
#242 opened by otherdaniel - 0
Broken references in HTML Sanitizer API
#232 opened by dontcallmedom-bot - 0
mXSS section outdated
#213 opened by lukewarlow - 1
Broken image in explainer.md
#230 opened by 22jcampb - 2
faq.md is outdated
#221 opened by lukewarlow - 3
Typos
#220 opened by lukewarlow - 3
Configuration edge cases
#198 opened by otherdaniel - 3
- 6
Remove __TO_BE_MERGED variants
#216 opened by foolip - 7
Trusted types API interaction
#204 opened by lukewarlow - 3
- 1
Links to Sanitizer API Defaults are broken
#205 opened by mbrodesser-Igalia - 0
Broken references in HTML Sanitizer API
#186 opened by dontcallmedom-bot - 20
Clarify threat model, "XSS first and foremost"
#188 opened by otherdaniel - 2
2023-09-20 meeting notes
#199 opened by evilpie - 17
Naming: flattenElements
#200 opened by annevk - 4
Unpublish current spec?
#207 opened by lukewarlow - 5
- 2
Custom data attributes (dataset / data-*) support
#191 opened by Janghou - 6
Should the sanitizer normalize
#203 opened by annevk - 3
2023-05-03 meeting notes
#192 opened by annevk - 1
Streaming support
#190 opened by zcorpan - 29
allowing unsafe markup
#185 opened by mozfreddyb