Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

XSS in href attribute, issue a warning #1864

Closed
m1212e opened this issue Jul 9, 2021 · 3 comments
Closed

XSS in href attribute, issue a warning #1864

m1212e opened this issue Jul 9, 2021 · 3 comments

Comments

@m1212e
Copy link

m1212e commented Jul 9, 2021

As stated in this issue, Sveltekit might be the right place to adress this.

@benmccann
Copy link
Member

@pngwn can you clarify what you had in mind in terms of SvelteKit doing about it?

@pngwn
Copy link
Member

pngwn commented Jul 11, 2021

No idea. But if we are going to solve this then we should be doing it in kit. I'll have a think.

@benmccann
Copy link
Member

You can address this with a content security policy (CSP): #93

I'm going to close this given that there's no concrete proposal for what we might do besides that

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants