15ae710d22
Allows sanitized URLs for CSS properties. These can be abused for information leakage, but only if the CSS rules are already set up to allow for it. That is, an attacker cannot cause information leakage without controlling the style rules present, or a very particular setup. Fixes #8514. |
||
---|---|---|
.. | ||
html_sanitizer_spec.ts | ||
style_sanitizer_spec.ts | ||
url_sanitizer_spec.ts |