Skip to content

Commit

Permalink
props-json security tip
Browse files Browse the repository at this point in the history
Fixes rstacruz#9.
  • Loading branch information
rybon authored Apr 23, 2019
1 parent 5fca9b9 commit 4541f1f
Showing 1 changed file with 2 additions and 0 deletions.
2 changes: 2 additions & 0 deletions docs/api.md
Original file line number Diff line number Diff line change
Expand Up @@ -99,6 +99,8 @@ While being more verbose than [named attributes](#named-attributes), it lets you

If a `props-json` property exists, all other named attributes will be ignored.

**NOTE:** Be careful when serializing arbitrary JSON into a `props-json` property, as it may inadvertently open a security hole for XSS. Use the [`serialize-javascript`](https://github.com/yahoo/serialize-javascript) package instead of `JSON.stringify` to be safe.

### Shadow DOM

Remount doesn't use Shadow DOM by default. To enable it, pass the `shadow: true` option.
Expand Down

0 comments on commit 4541f1f

Please sign in to comment.