Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
securitymb
on Oct 7, 2020
|
parent
|
context
|
favorite
| on:
DOMPurify bypass: XSS via HTML namespace confusion
This would work and this something that Angular DomSanitizer does [1]. But I personally am not a big fan of this solution as it has large performance penalty if the sanitized string is huge.
[1]
https://github.com/angular/angular/blob/2038568f3e631cb15e91...
Join us for
AI Startup School
this June 16-17 in San Francisco!
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search:
[1] https://github.com/angular/angular/blob/2038568f3e631cb15e91...