Skip to content

fix(many): innerHTML is disabled by default #27029

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 2 commits into from
Mar 27, 2023
Merged

Conversation

liamdebeasi
Copy link
Contributor

@liamdebeasi liamdebeasi commented Mar 27, 2023

Pull request checklist

Please check if your PR fulfills the following requirements:

  • Tests for the changes have been added (for bug fixes / features)
  • Docs have been reviewed and added / updated if needed (for bug fixes / features)
    • Some docs updates need to be made in the ionic-docs repo, in a separate PR. See the contributing guide for details.
  • Build (npm run build) was run locally and any changes were pushed
  • Lint (npm run lint) has passed locally and any fixes were made for failures

Pull request type

Please check the type of change your PR introduces:

  • Bugfix
  • Feature
  • Code style update (formatting, renaming)
  • Refactoring (no functional changes, no api changes)
  • Build related changes
  • Documentation content changes
  • Other (please describe):

What is the current behavior?

As per the innerHTMLTemplatesEnabled design doc, this flag should default to false on Ionic 7 to de-risk the use of innerHTML functionality in Ionic. This change requires developers to opt-in to dangerously setting innerHTML content inside of Ionic components. As a result of this change (and combined with documentation published on our site), developers should be more informed of the risks of using innerHTML as well as the need for using a reliable sanitizer if they choose to use innerHTML.

What is the new behavior?

  • innerHTMLTemplatesEnabled defaults to false.

Does this introduce a breaking change?

  • Yes
  • No

Other information

@bolt-new-by-stackblitz
Copy link

Review PR in StackBlitz Codeflow Run & review this pull request in StackBlitz Codeflow.

@github-actions github-actions bot added the package: core @ionic/core package label Mar 27, 2023
@liamdebeasi liamdebeasi marked this pull request as ready for review March 27, 2023 15:54
@liamdebeasi liamdebeasi requested a review from a team as a code owner March 27, 2023 15:54
@liamdebeasi liamdebeasi merged commit b7e4603 into feature-7.0 Mar 27, 2023
@liamdebeasi liamdebeasi deleted the html-disable-v7 branch March 27, 2023 16:07
@lincolnthree
Copy link

@brandyscarney @liamdebeasi the typedoc should probably be updated for this in ionic config, too, I think, right?

https://github.com/ionic-team/ionic-framework/blob/v7.0.0-rc.4/core/src/utils/config.ts#L193

@liamdebeasi
Copy link
Contributor Author

Fixed: #27032

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
package: core @ionic/core package
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants