top | item 21069557

(no title)

zawerf | 6 years ago

It wouldn't help if new features extend the capabilities of existing stuff (which is done all the time). For example the CSS Shader example from before adds new syntax to the existing 'filter' css style, which you might've already whitelisted because it is safe today.

discuss

order

ShaneCurran|6 years ago

I guess a nested, parameter-granularity whitelist would work in that case :)

_urga|6 years ago

You can do that with DOMPurify using hooks.