x-style icon indicating copy to clipboard operation
x-style copied to clipboard

Disable x-style in some parts of the DOM

Open alarbada opened this issue 2 years ago • 2 comments

Following this: https://htmx.org/docs/#security

This library looks really interesting! But I believe it could have some security issues with uploaded user html from a WYSIWYG, for example.

alarbada avatar Jun 16 '23 07:06 alarbada

Good catch, I will add a similar 'x-style-disable' attribute.

Realistically, user submitted html needs to be going through an "allow list" (rather than block list) of elements and attributes. But not everyone is that thorough though.

samwillis avatar Jun 16 '23 09:06 samwillis