Skip to content

Conversation

lionel-rowe
Copy link

Closes #112

I think it's best _not_ to try to prevent XSS within the demo so users can accurately
see the results _without_ any sanitization, but users should at least be able to test
things like <img src=x onerror=alert(1)> within the editor without causing infinite
loops. Triggering on keyup was causing the alert to be re-fired upon pressing Escape
to close it.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Mutation XSS + general sanitization

1 participant