-
Notifications
You must be signed in to change notification settings - Fork 81
Closed
Labels
position: positivevenue: W3C CGSpecifications in W3C Community Groups (e.g., WICG, Privacy CG)Specifications in W3C Community Groups (e.g., WICG, Privacy CG)
Description
Request for Mozilla Position on an Emerging Web Specification
- Specification Title: Sanitize Untrusted HTML
- Specification or proposal URL: https://github.com/WICG/purification
- Caniuse.com URL (optional): N/A
- Bugzilla URL (optional): N/A
- Mozillians who can provide input (optional): @ckerschb, @dveditz,
Other information
NB: This is an early stage exploration. @marcoscaceres suggested I file this, so here we go.
XSS (and lately, DOM XSS) is an ongoing struggle for web application developers - increasingly with the rise of so-called Single Page Applications.
We think there's value in getting a simple, single use-case API into browsers, that helps developers avoid brittle JS solutions, which suffer from DOM clobbering and cross-browser ambiguities. For more, please refer to the explainer doc.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
position: positivevenue: W3C CGSpecifications in W3C Community Groups (e.g., WICG, Privacy CG)Specifications in W3C Community Groups (e.g., WICG, Privacy CG)