You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
background-image is not included in SafeList::ALLOWED_CSS_PROPERTIES
I want to enable till to set background-image as a url.
What are potential risk and things I should consider while doing this.
My usecase is while using rails action text.
Thanks for the help.
The text was updated successfully, but these errors were encountered:
Hi @puneet-sutar - attributes that cause loading of external assets via URLs/URIs are sanitized.
Please also note that Loofah doesn't have an opinion here, we're using the attributes from HTML5Lib; and #155 proposes using DomPurify. Both of these packages do not consider background-image to be safe.
background-image
is not included inSafeList::ALLOWED_CSS_PROPERTIES
I want to enable till to set background-image as a url.
What are potential risk and things I should consider while doing this.
My usecase is while using rails action text.
Thanks for the help.
The text was updated successfully, but these errors were encountered: