js-xss
js-xss copied to clipboard
why i use xssFilter({ css: false }) is not take effect?
var myxss = new xss.FilterXSS({
css: false,
});
myxss(<span style=\"color:#f39c12\">123</span>) // => <span>123</span> i need style attr
me too!
By default any style
attribute is removed, so you also need to allow it.
From the README.md
If you allow the attribute
style
, the value will be processed by cssfilter module.
me too!