Skip to content

Conversation

@stephannv
Copy link
Owner

Raises error when attribute name includes not allowed characters.

Now that Hash attributes are accepted, we should not permit attributes like:

a({ %(onclick="xss" class) => "btn" })

Without this protection the code above would render:

<a onclick="xss" class="btn"></a>

@stephannv stephannv self-assigned this Dec 28, 2025
@stephannv stephannv force-pushed the attribute_name_safety branch from eb36e57 to f2fdd3a Compare December 28, 2025 21:12
@stephannv stephannv merged commit 9fe215f into main Dec 28, 2025
1 check passed
@stephannv stephannv deleted the attribute_name_safety branch December 28, 2025 21:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants