OWASP / java-html-sanitizer

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.
Other
833 stars 210 forks source link

Question: What means Recognize foreign content syntactic context: mathml / svg? #332

Open RyosukeFukatani opened 3 months ago

RyosukeFukatani commented 3 months ago

In release note .

HTML: Recognize foreign content syntactic context: mathml / svg.

Could you be more specific about the change in behavior when viewed as a black box? We would appreciate it if you could provide us with a test case for the specific change in behavior that will result from this change.

I found PR https://github.com/OWASP/java-html-sanitizer/pull/318/files, but I could not understand the change in behavior when MathML input is used.